Description
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Code Execution
Action: Upgrade Immediately
AI Analysis

Impact

The vulnerability allows the Camel AI CodeExecutionToolkit to run model‑produced Python code via a SubprocessInterpreter without any approval, enabling an attacker to execute arbitrary code in the host environment. This can compromise confidentiality, integrity, and availability of the system when a malicious model output is processed.

Affected Systems

Camel‑AI camel library versions 0.2.91a1, 0.2.91a2 and 0.2.91a3 are affected. No other product or version information is listed.

Risk and Exploitability

No CVSS score is available, but the absence of an approval boundary creates a clear path for code execution. The EPSS score is not provided, and the vulnerability is not catalogued in CISA KEV. The likely attack vector is the insertion of malicious content into a model’s prompt or dataset, with backend systems executing it without verification. This represents a high‑impact risk if the application processes untrusted inputs.

Generated by OpenCVE AI on September 30, 2026 at 23:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade camel‑ai camel to a version released after 0.2.91a3 that includes the code‑execution restriction fix.
  • Disabling or removing the CodeExecutionToolkit or SubprocessInterpreter component from the application configuration if an upgrade is not immediately possible.
  • Implement an explicit approval or whitelisting mechanism within the application to restrict execution of model‑generated code, ensuring only trusted code is run.

Generated by OpenCVE AI on September 30, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Python Code Execution via SubprocessInterpreter in Camel AI
Weaknesses CWE-94

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:52:34.580Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51857

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.647

Modified: 2026-09-30T21:17:11.647

Link: CVE-2026-51857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')