๐Ÿ” CVE Alert

CVE-2026-18980

MEDIUM 6.3

nearai ironclaw shell.rs classify_command_risk command injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.

CWE CWE-77 CWE-74
Vendor nearai
Product ironclaw
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for nearai ironclaw

Be the first to know when new medium vulnerabilities affecting nearai ironclaw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

nearai / ironclaw
0.29.0 0.29.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/386265 vuldb.com: https://vuldb.com/vuln/386265/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18980 vuldb.com: https://vuldb.com/submit/862542 vuldb.com: https://vuldb.com/submit/862543 vuldb.com: https://vuldb.com/submit/862544 vuldb.com: https://vuldb.com/submit/862545 vuldb.com: https://vuldb.com/submit/862546 github.com: https://github.com/nearai/ironclaw/issues/4861 github.com: https://github.com/nearai/ironclaw/pull/4869 github.com: https://github.com/nearai/ironclaw/issues/4862 github.com: https://github.com/nearai/ironclaw/commit/a1d7c3ba428ed575900469b207fb5668725f9a71 github.com: https://github.com/nearai/ironclaw/

Credits

๐Ÿ” Erichen-apple (VulDB User)