CVE-2026-18980
Severity CVSS v4.0:
LOW
Type:
CWE-74
Injection
Publication date:
06/08/2026
Last modified:
12/08/2026
Description
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/nearai/ironclaw/
- https://github.com/nearai/ironclaw/commit/a1d7c3ba428ed575900469b207fb5668725f9a71
- https://github.com/nearai/ironclaw/issues/4861
- https://github.com/nearai/ironclaw/issues/4862
- https://github.com/nearai/ironclaw/pull/4869
- https://vuldb.com/cve/CVE-2026-18980
- https://vuldb.com/submit/862542
- https://vuldb.com/submit/862543
- https://vuldb.com/submit/862544
- https://vuldb.com/submit/862545
- https://vuldb.com/submit/862546
- https://vuldb.com/vuln/386265
- https://vuldb.com/vuln/386265/cti
- https://github.com/nearai/ironclaw/issues/4861
- https://vuldb.com/submit/862542
- https://vuldb.com/submit/862543
- https://vuldb.com/submit/862544
- https://vuldb.com/submit/862545
- https://vuldb.com/submit/862546



