What is CVE-2026-18980?
A command injection vulnerability was identified in the `classify_command_risk` function of nearai ironclaw up to version 0.29.1. This allows remote attackers to execute arbitrary commands, and a public exploit is available. Immediate upgrade to the latest version is strongly recommended.
Azərbaycanca: nearai ironclaw alətinin 0.29.1-ə qədər versiyalarında `classify_command_risk` funksiyasında əmr inyeksiyası zəifliyi aşkar edilib. Bu zəiflik uzaqdan hücum etməyə imkan verir və təsdiqlənmiş istismar kodu mövcuddur. Dərhal son versiyaya yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What is the CVE-2026-18980 vulnerability found in nearai ironclaw?
It is a command injection vulnerability in the `classify_command_risk` function, allowing remote attackers to execute arbitrary commands.
How can users protect themselves against CVE-2026-18980?
This vulnerability affects nearai ironclaw versions up to 0.29.1. An immediate upgrade to the latest version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.