CVE-2026-16204

MEDIUM

zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection

Title source: cna
STIX 2.1

Description

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-380020 | zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
https://vuldb.com/vuln/380020
Signature, Permissions Required signature permissions-required
VDB-380020 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/380020/cti
Third Party Advisory third-party-advisory
CVE-2026-16204 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16204
Third Party Advisory third-party-advisory
Submit #857784 | zevorn rt-claw 36d128f72afa0b9d40a21bcd6069b0c193a58f82 (unreleased main, post-v0.2.0) Remote Code Execution via Unsafe Tool Auto-Approval (CWE-94)
https://vuldb.com/submit/857784
Exploit exploit issue-tracking
https://github.com/zevorn/rt-claw/issues/138

Scores

CVSS v3 6.3
EPSS 0.0031
EPSS Percentile 23.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-94
Status published
Products (2)
zevorn/rt-claw 0.1
zevorn/rt-claw 0.2.0
Published Jul 19, 2026
Tracked Since Jul 19, 2026