Impact
The vulnerability is a code injection flaw located in the tool_run_script_execute function inside the claw/services/tools/script.c component of the rt‑claw Telegram‑to‑AI Tool Execution Flow. When an attacker manipulates the input to this function, arbitrary code can be injected and executed, resulting in full remote code execution. The weakness is classified as CWE‑74 and CWE‑94, indicating insufficient input validation and improper handling of executable code.
Affected Systems
The flaw affects zevorn:rt-claw versions up to 0.2.0. This includes all installations of the Telegram‑to‑AI Tool that use the vulnerable script.c module. No additional product or version details are disclosed.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate range, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, but public exploit code is available, which raises the risk of targeted attacks. Because the vulnerability can be triggered remotely via manipulation of input to the script execution API, the threat remains present for all affected systems that have not applied a fix.
OpenCVE Enrichment