Impact
A vulnerability exists in Nearai Ironclaw up to version 0.29.1 in the classify_command_risk function within src/tools/builtin/shell.rs. The flaw allows attackers to inject arbitrary shell commands, potentially executing malicious code with the privileges of the Ironclaw service. This weakness would compromise confidentiality, integrity, and availability of the affected system, allowing the attacker to extract sensitive data, modify or delete files, or use the host as a foothold for further attacks. The weakness is represented by CWE‑74 and CWE‑77.
Affected Systems
All releases of Nearai Ironclaw, including every version up to and including 0.29.1, are vulnerable. Newer releases incorporating the patch from commit a1d7c3ba428ed575900469b207fb5668725f9a71 provide remediation.
Risk and Exploitability
The vulnerability can be exploited remotely and a publicly available exploit has been identified. The CVSS score of 5.3 indicates moderate severity, but the EPSS score of 1% indicates a very low but nonzero likelihood of exploitation. The issue is not currently listed in CISA’s KEV catalog. An attacker could leverage this flaw by sending crafted input to the classify_command_risk interface from an external network, provided the interface is reachable. If no network segmentation or authentication controls are in place, the attack surface is wide. Given the public availability of the exploit, it is advisable to treat this exposure as a likely risk.
OpenCVE Enrichment