Impact
TerminalToolkit.shell_exec in camel-ai camel versions 0.2.91a1 through 0.2.91a3 permits the execution of arbitrary shell commands when a user is presented with a prompt, but the code does not enforce any approval or validation boundary. This flaw is a classic example of command injection (CWE-78), which could compromise the confidentiality, integrity, or availability of the system where the vulnerable component runs by allowing an attacker to execute arbitrary OS commands. The vulnerability is not limited to a local context; if the TerminalToolkit interface is exposed over a network or can be invoked by remote users, it becomes a vector for remote code execution.
Affected Systems
The issue affects the camel-ai camel library in versions 0.2.91a1, 0.2.91a2, and 0.2.91a3. No other versions were listed as affected by the CVE entry. The specific vendor product name is camel-ai camel.
Risk and Exploitability
The public CVSS score is not provided in the data, and EPSS is listed as not available. Because the flaw allows unrestricted command execution, it is highly exploitable if an attacker can trigger the prompt. The KEV catalog does not list this vulnerability, indicating no known widespread exploitation at the time of the data. The likely attack vector is a local or remote prompt that initiates TerminalToolkit.shell_exec; the lack of an approval boundary means the attacker can inject any shell command. With administrative or sufficient user privileges, exploitation could lead to full system compromise.
OpenCVE Enrichment