CVE-2026-25130Disclosure

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `shell=True`, allowing attackers to execute arbitrary commands on the host system. The `find_file()` tool executes without requiring user approval because find is considered a "safe" pre-approved command. This means an attacker can achieve Remote Code Execution (RCE) by injecting malicious arguments (like -exec) into the args parameter, completely bypassing any human-in-the-loop safety mechanisms. Commit e22a1220f764e2d7cf9da6d6144926f53ca01cde contains a fix.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-01-30); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-01-30: 4Mentions · 2026-01-31: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-01: 1Technical Details · 2026-01-30: 4Technical Details · 2026-01-31: 1Technical Details · 2026-02-01: 101-3001-3102-0102-02
Signal classification3 categories
Disclosure
571.4%
PoC
114.3%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-304
Disclosure4
2026-01-311
Disclosure1
2026-02-011
PoC1
2026-02-021
General1
Full discourse7 posts
  • Averlon@Averlon_ai
    General

    When a new vulnerability drops, chaos follows. Advisories flood in. Hot takes spread. Everyone asks: “How bad is this?” But the harder question is: "When does this vulnerability actually matter, and why?" Today, security teams spend 15–60 minutes per CVE jumping between: CVE reports, advisories, blog posts, vendor commentary, and research notes just to answer that. Vulnerability Intelligence exists to collapse that work. For each CVE, it breaks down: • what the vulnerability actually is • what an attacker would need to exploit it • whether user interaction or access is required • whether it’s being exploited in the wild This is the reasoning layer teams usually have to reconstruct manually. We’ve made this available as a free resource for security teams who need clarity before decisions. Live example: https://research.averlon.ai/vulnerability-intelligence/cve/CVE-2026-25130

    Post summary

    The post promotes a free resource that compiles and clarifies CVE information for security teams, but it does not mention any PoC, exploit code, patch, technical details, or evidence of active exploitation.

    0003087
    37 followersView on X
  • S.Komichevsen Matsuk@w4yh
    PoC

    CVE-2026-25130の解説がPoCというかthat's allな感が // CAI find_file Agent Tool has Command Injection Vulnerability Through Argument Injection · CVE-2026-25130 · GitHub Advisory Database https://github.com/advisories/GHSA-jfpc-wj3m-qw2m

    Post summary

    The post references CVE‑2026‑25130 as a command‑injection flaw, notes an accompanying explanation that resembles a proof‑of‑concept, but provides no exploit code, patch information, or evidence of active exploitation.

    00000187
    326 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    CAI framework's find_file Agent Tool has a command injection vulnerability (CVE-2026-25130) through argument injection. Assess usage of this tool with untrusted input. #CAIFramework #InfoSec #Cybersecurity https://www.pulsepatch.io/posts/cve-2026-25130-cai-framework-command-injection

    Post summary

    The post discloses a command injection flaw (CVE‑2026‑25130) in CAI framework’s find_file agent tool and urges assessing its use with untrusted input.

    0000073
    1 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25130: CRITICAL] Beware of Cybersecurity AI (CAI) framework versions up to 0.5.10! Multiple argument injection vulnerabilities could allow attackers to execute commands on host system. Check commit...#cve,CVE-2026-25130,#cybersecurity https://cvefind.com/CVE-2026-25130

    Post summary

    The message alerts readers to a critical argument injection flaw in the Cybersecurity AI framework (v0.5.10 and earlier) that could enable host command execution, but offers no PoC, exploit, or patch information.

    0000051
    584 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25130 - Critical Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in... https://www.thehackerwire.com/vulnerability/CVE-2026-25130/ https://t.co/0hOw2wf62o

    Post summary

    The tweet announces CVE‑2026‑25130 as a critical argument injection flaw affecting CAI framework versions up to 0.5.10, with a link to further details.

    0000060
    113 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25130 Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injecti… https://www.cve.org/CVERecord?id=CVE-2026-25130

    Post summary

    The passage discloses CVE-2026-25130 as a vulnerability in Cybersecurity AI (CAI) involving argument injection in versions up to 0.5.10, without providing any PoC, exploit, or mitigation details.

    00000174
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25130: Cybersecurity AI vulnerable to c... Classic subprocess.Popen() with shell=True strikes again – CAI's "safe" find_file() tool enables unapproved RCE via arg... https://zerodaysignal.com/vulnerability/CVE-2026-25130 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑25130, detailing an RCE via the CAI find_file() tool using subprocess.Popen(), but lacks a patch notice, PoC, or evidence of active exploitation.

    0000073
    132 followersView on X

Explore more