CVE-2026-3964General

LOWCVSS 1.9 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Chat API Endpoint. Executing a manipulation of the argument Message can lead to os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2PoC Mentioned / Linked · 2026-03-12: 1Technical Details · 2026-03-12: 103-12
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-3964 A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Chat API Endpoint. Exe… https://www.cve.org/CVERecord?id=CVE-2026-3964

    Post summary

    The advisory notes a weakness in OpenAkita's Chat API Endpoint affecting the run function in shell.py, but offers no deeper technical details or mitigation information.

    00000118
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    PoC

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3964 - OpenAkita Chat API Endpoint http://shell.py run os command injection Intel Report: https://ift.tt/vWPstpb

    Post summary

    The post announces CVE‑2026‑3964, cites an endpoint that likely hosts a proof‑of‑concept for OS command injection, but offers no active exploitation evidence, patches, or detailed exploit code.

    0000024
    342 followersView on X

Explore more