Description
A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: 1.3% Low
KEV: No
Impact: Remote Command Execution
Action: Patch or Mitigate
AI Analysis

Impact

A flaw in HKUDS AnyTool 0.1.0 allows an attacker to supply arbitrary values to the command and shell arguments of the subprocess.run call in the Execute Endpoint. The vulnerability permits execution of arbitrary operating‑system commands, which can lead to complete compromise of the host machine if the application runs with elevated privileges. The weakness maps to CWE‑77 (OS Command Injection) and CWE‑78 (Improper Neutralization of Special Elements used in a Command).

Affected Systems

The affected product is HKUDS AnyTool, version 0.1.0. The vulnerability resides in the Execute Endpoint component, specifically the main.py file that handles remote requests. No additional product versions or vendor variants are listed.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity with potential for remote exploitation. EPSS score of 1% suggests a very low but non‑zero likelihood of exploitation, though the description states that the exploit is publicly available and could be used. The vulnerability is not listed in CISA KEV. The likely attack vector is remote, originating from an authenticated or unauthenticated requester that can configure the command or shell parameters over the network. Successful exploitation would allow arbitrary code execution on the host and could facilitate lateral movement, data exfiltration, or denial of service.

Generated by OpenCVE AI on September 30, 2026 at 15:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patched release of HKUDS AnyTool that removes the vulnerable subprocess.run usage; if no patch exists, uninstall or disable the Execute Endpoint component.
  • Limit network exposure of the AnyTool service by restricting inbound traffic to trusted IPs or requiring strong authentication before allowing access to the Execute Endpoint.
  • Modify the code (if possible) to eliminate the use of shell=True in subprocess.run, or validate and sanitize all command and shell parameters before execution; alternatively, replace the vulnerable call with a safer API that does not interpret shell syntax.

Generated by OpenCVE AI on September 30, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection
First Time appeared Hkuds
Hkuds anytool
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:hkuds:anytool:*:*:*:*:*:*:*:*
Vendors & Products Hkuds
Hkuds anytool
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T13:54:31.248Z

Reserved: 2026-09-29T17:31:08.600Z

Link: CVE-2026-102874

cve-icon Vulnrichment

Updated: 2026-09-30T13:54:27.260Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T03:16:57.503

Modified: 2026-09-30T14:17:25.147

Link: CVE-2026-102874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T15:15:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')