Impact
An OS command injection exists in the killSessionSync function of 23blocks‑OS ai‑maestro, allowing an attacker who can supply crafted input to execute arbitrary shell commands on the host. This vulnerability provides an attacker with the ability to fully compromise the affected system, including persisting malicious activity, exfiltrating data, or pivoting within the environment. The exploit requires the ability to invoke the function with injected arguments, and the impact spans confidentiality, integrity, and availability of the compromised machine.
Affected Systems
The only version explicitly listed as vulnerable is 23blocks‑OS ai‑maestro v0.24.17. No other products or versions are mentioned in the available data. This version is the sole affected point in the current advisory.
Risk and Exploitability
The CVSS score is 9.8, and the EPSS score is 0.01605 (~1.6%), but the vulnerability is not recorded in the CISA KEV catalog. Based on the description, it is inferred that the function may be exposed through a network‑accessible API or command interface, which would allow remote attackers to exercise the injection. Because OS command injection can lead to remote code execution, the risk is inherently high, though the precise exploitability depends on the function’s exposure and the system’s network posture. The EPSS score indicates a low but non‑zero probability of exploitation globally, yet the potential damage remains significant if the function is reachable from untrusted clients.
OpenCVE Enrichment