PT-2026-60977 · Princezuda · Safestclaw

·

CVE-2026-16129

·

Published

2026-07-18

·

Updated

2026-07-18

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions princezuda SafestClaw versions prior to 4.2.5
Description An issue exists in the Built-in Web Interface within the ShellAction. validate command() function located in the src/safestclaw/actions/shell.py file. This flaw results in an incomplete blacklist, which could be exploited by a local attacker.
Recommendations Update princezuda SafestClaw to version 4.2.5 or later. As a temporary mitigation, restrict local access to the Built-in Web Interface or avoid using the ShellAction. validate command() function.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16129

Affected Products

Safestclaw