CVE-2026-25130
CRITICALCAI Framework <= 0.5.10 - Remote Code Execution via Argument Injection in find_file Tool
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-25130. PoCs published by XiaomingX, mbanyamer.
AI-analyzed exploit summary This repository contains a functional SQL injection exploit for WordPress Quiz Maker (CVE-2025-10042), demonstrating time-based blind SQLi via crafted HTTP headers. The exploit includes methods for vulnerability detection, data extraction, and credential dumping.
Description
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `shell=True`, allowing attackers to execute arbitrary commands on the host system. The `find_file()` tool executes without requiring user approval because find is considered a "safe" pre-approved command. This means an attacker can achieve Remote Code Execution (RCE) by injecting malicious arguments (like -exec) into the args parameter, completely bypassing any human-in-the-loop safety mechanisms. Commit e22a1220f764e2d7cf9da6d6144926f53ca01cde contains a fix.
Exploits (2)
This repository contains a functional SQL injection exploit for WordPress Quiz Maker (CVE-2025-10042), demonstrating time-based blind SQLi via crafted HTTP headers. The exploit includes methods for vulnerability detection, data extraction, and credential dumping.
This PoC demonstrates an argument injection vulnerability in the Cybersecurity AI (CAI) Framework's `find_file` function, leading to OS command injection. It includes tests for command execution, file creation, and a commented reverse shell example.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H