Impact
The vulnerability allows the Camel AI CodeExecutionToolkit to run model‑produced Python code via a SubprocessInterpreter without any approval, enabling an attacker to execute arbitrary code in the host environment. This can compromise confidentiality, integrity, and availability of the system when a malicious model output is processed.
Affected Systems
Camel‑AI camel library versions 0.2.91a1, 0.2.91a2 and 0.2.91a3 are affected. No other product or version information is listed.
Risk and Exploitability
No CVSS score is available, but the absence of an approval boundary creates a clear path for code execution. The EPSS score is not provided, and the vulnerability is not catalogued in CISA KEV. The likely attack vector is the insertion of malicious content into a model’s prompt or dataset, with backend systems executing it without verification. This represents a high‑impact risk if the application processes untrusted inputs.
OpenCVE Enrichment