Description
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary shell command execution
Action: Upgrade or patch
AI Analysis

Impact

TerminalToolkit.shell_exec in camel-ai camel versions 0.2.91a1 through 0.2.91a3 permits the execution of arbitrary shell commands when a user is presented with a prompt, but the code does not enforce any approval or validation boundary. This flaw is a classic example of command injection (CWE-78), which could compromise the confidentiality, integrity, or availability of the system where the vulnerable component runs by allowing an attacker to execute arbitrary OS commands. The vulnerability is not limited to a local context; if the TerminalToolkit interface is exposed over a network or can be invoked by remote users, it becomes a vector for remote code execution.

Affected Systems

The issue affects the camel-ai camel library in versions 0.2.91a1, 0.2.91a2, and 0.2.91a3. No other versions were listed as affected by the CVE entry. The specific vendor product name is camel-ai camel.

Risk and Exploitability

The public CVSS score is not provided in the data, and EPSS is listed as not available. Because the flaw allows unrestricted command execution, it is highly exploitable if an attacker can trigger the prompt. The KEV catalog does not list this vulnerability, indicating no known widespread exploitation at the time of the data. The likely attack vector is a local or remote prompt that initiates TerminalToolkit.shell_exec; the lack of an approval boundary means the attacker can inject any shell command. With administrative or sufficient user privileges, exploitation could lead to full system compromise.

Generated by OpenCVE AI on September 30, 2026 at 23:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update camel-ai camel to a version that fixes TerminalToolkit.shell_exec or remove the vulnerable library entirely
  • Disable or restrict calls to TerminalToolkit.shell_exec and enforce an approval boundary before any command is executed
  • Ensure that only trusted users or services have the ability to trigger shell execution, and run the application with the least privileged account needed

Generated by OpenCVE AI on September 30, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Shell Command Execution via TerminalToolkit.shell_exec without Approval Boundary
Weaknesses CWE-78

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:53:20.766Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:11.777

Modified: 2026-09-30T21:17:11.777

Link: CVE-2026-51858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')