Vulnerability Description
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/23blocks-OS/ai-maestro/commit/06d54f0687ad1fc5898a688a92f7e1f
- https://github.com/23blocks-OS/ai-maestro/security/advisories/GHSA-mf7j-vfrr-jmf
- https://github.com/rajukani100/CVE-research/tree/main/ai-maestro-rce-advisory
- https://github.com/rajukani100/CVE-research/tree/main/ai-maestro-rce-advisory
FAQ
What is CVE-2026-37751?
CVE-2026-37751 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
How severe is CVE-2026-37751?
CVE-2026-37751 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-37751?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.