CVE-2025-67511

CRITICAL

Pypi Cai-framework - Command Injection

Title source: rule
STIX 2.1

Description

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.

Scores

CVSS v3 9.6
EPSS 0.0020
EPSS Percentile 41.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
aliasrobotics/cai <= 0.5.9
aliasrobotics/cybersecurity_ai < 0.5.9
pypi/cai-framework 0PyPI
Published Dec 11, 2025
Tracked Since Feb 18, 2026