PT-2026-40103 · Junoclaw · Junoclaw

CVE-2026-43991

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JunoClaw versions prior to 0.x.y-security-1
Description A substring-based blocklist in the plugin-shell command-safety check can be bypassed using adversarial argument constructions. This occurs because the check is applied to the raw command string instead of the parsed first token, which may allow unauthorized command execution on the host.
Recommendations Update to version 0.x.y-security-1.

Exploit

Fix

Incomplete List of Disallowed Inputs

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43991
GHSA-FVQ5-79H6-952C

Affected Products

Junoclaw