Impact
The vulnerability exists in parse_url.ts of Personal_AI_Infrastructure. An attacker can exploit an unvalidated function that parses URLs, causing the application to invoke arbitrary operating‑system commands. This allows remote command execution, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
danielmiessler’s Personal_AI_Infrastructure is affected up to version 2.3.0. All installations running this or earlier versions are vulnerable, regardless of deployment method.
Risk and Exploitability
The severity score of 5.3 indicates moderate risk, but the nature of the flaw—command injection—makes exploitation highly impactful. Public disclosure and a remote attack vector through crafted URL input raise the likelihood of real-world attacks. No EPSS data or KEV listing is available, so precise exploit probability is unknown, but the vulnerability can be triggered with standard input handling.
OpenCVE Enrichment