Impact
The vulnerability resides in the executeCognitivePulse function in src/kernel.ts of the 8421bit MiniClaw application. Exploiting it enables an attacker to inject arbitrary operating‑system commands to be executed by the running process. The flaw falls under CWE-77 and CWE-78 and could lead to Remote Command Execution, compromising confidentiality, integrity, and availability of the system.
Affected Systems
MiniClaw is distributed by 8421bit. The vulnerability affects all releases up to commit 223c16a1088e138838dcbd18cd65a37c35ac5a84. As the project uses a rolling release model, specific version applicability is not pinpointed, so any currently running instance without the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS value is available, but the vulnerability is public and the exploit code has been released. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger it remotely, likely via network interfaces that expose the executeCognitivePulse function.
OpenCVE Enrichment