PT-2026-86392 · Cua · Computer-Server
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cua computer-server versions prior to 0.3.42
Description
Authentication is bypassed when the
CONTAINER NAME environment variable is unset, as the server binds to all interfaces by default. This allows unauthenticated attackers to execute arbitrary commands via the 'run command' endpoint, perform read and write operations on arbitrary files through file operation endpoints, and access interactive PTY shells.Recommendations
Update Cua computer-server to version 0.3.42 or later.
Ensure the
CONTAINER NAME environment variable is properly set to enable authentication.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Computer-Server