GHSA-gcxx-4qc7-cmmwCriticalCVSS 9.8

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of...

Published
August 28, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

🔗 References (5)