Impact
A flaw in HKUDS AnyTool 0.1.0 allows an attacker to supply arbitrary values to the command and shell arguments of the subprocess.run call in the Execute Endpoint. The vulnerability permits execution of arbitrary operating‑system commands, which can lead to complete compromise of the host machine if the application runs with elevated privileges. The weakness maps to CWE‑77 (OS Command Injection) and CWE‑78 (Improper Neutralization of Special Elements used in a Command).
Affected Systems
The affected product is HKUDS AnyTool, version 0.1.0. The vulnerability resides in the Execute Endpoint component, specifically the main.py file that handles remote requests. No additional product versions or vendor variants are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity with potential for remote exploitation. EPSS score of 1% suggests a very low but non‑zero likelihood of exploitation, though the description states that the exploit is publicly available and could be used. The vulnerability is not listed in CISA KEV. The likely attack vector is remote, originating from an authenticated or unauthenticated requester that can configure the command or shell parameters over the network. Successful exploitation would allow arbitrary code execution on the host and could facilitate lateral movement, data exfiltration, or denial of service.
OpenCVE Enrichment