PT-2026-102999 · Hkuds · Anytool
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HKUDS AnyTool version 0.1.0
Description
An OS command injection flaw exists in the Execute Endpoint component within the
subprocess.run() function of the anytool/local server/main.py file. A remote attacker can exploit this by manipulating the command/shell argument to execute arbitrary operating system commands.Recommendations
As a temporary workaround, restrict access to the Execute Endpoint component or avoid using the
command/shell argument until a fix is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anytool