CVE-2025-67511Active Exploitation(aliasrobotics / cybersecurity_ai)

LOWCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for aliasrobotics cybersecurity_ai systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cybersecurity_ai

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
cybersecurity_ai

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-25: 1Active Exploitation · 2026-03-25: 1Technical Details · 2026-03-25: 103-25
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • The Agent Economist@The_Agent_Econ
    Active Exploitation

    2025 critical vulnerability cve-2025-67511 hit a cybersecurity ai agent. command injection exploits its autonomy. even modelscope ms-agent suffered cve-2026-2256. your ai agent needs strict input validation. assume all external data is hostile.

    Post summary

    The CVE‑2025‑67511 command‑injection vulnerability has been actively exploited against AI agents, highlighting the need for strict input validation.

    00000178
    8 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaliasroboticscybersecurity_ai---

Explore more