PT-2026-60977 · Princezuda · Safestclaw
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
princezuda SafestClaw versions prior to 4.2.5
Description
An issue exists in the Built-in Web Interface within the
ShellAction. validate command() function located in the src/safestclaw/actions/shell.py file. This flaw results in an incomplete blacklist, which could be exploited by a local attacker.Recommendations
Update princezuda SafestClaw to version 4.2.5 or later.
As a temporary mitigation, restrict local access to the Built-in Web Interface or avoid using the
ShellAction. validate command() function.Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Safestclaw