Impact
FinRobot version 1.0.0 contains a code injection flaw in the CodingUtils.modify_code function. The flaw allows a malicious actor to inject and execute arbitrary code at runtime, giving full control over the application and its underlying system. This results in compromise of confidentiality, integrity and availability of the asset running the application.
Affected Systems
The vulnerability is present in the FinRobot v1.0.0 product. No vendor or product variants are listed, indicating that only this specific release is affected.
Risk and Exploitability
Without an EPSS score or CVSS rating, the exact exploitation probability and severity are not quantified, but code injection is a well‑known high‑risk weakness. The vulnerability is not listed in CISA’s KEV catalog, so no known exploits have been reported yet. However, the attack vector is likely local or remote if the application is exposed to untrusted input. An attacker would need to supply crafted input to the modify_code function; once triggered, code runs with the application’s privileges.
OpenCVE Enrichment