Impact
The vulnerability resides in the shell tool command allowlist of the OpenHuman desktop agent's SecurityPolicy, allowing a bypass that results in arbitrary OS command execution with the privileges of the desktop user. This flaw is a Command Injection issue involving CWE-184 and CWE-78. An attacker who can supply a malicious command string to the agent can execute any system command.
Affected Systems
The affected product is the OpenHuman desktop agent from tinyhumansai. Versions up to and including 0.54.0, which use the default Supervised security policy, are vulnerable. It is unclear whether later releases are still affected until an official fix is released.
Risk and Exploitability
The CVSS score of 9.4 marks a high severity remote code execution. EPSS indicates a low exploitation probability (<1%), and it is not listed in CISA's KEV catalog. Based on the description, the attack requires the agent to process a malicious input that defeats the allowlist, giving an attacker full command execution on the user’s machine.
OpenCVE Enrichment