ZeroHour

CVE-2026-37751

niche

OS Command Injection in 23blocks-OS ai-maestro v0.24.17

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
AI analysis

CVE-2026-37751 is an OS command injection vulnerability (CWE-78) in the killSessionSync function in lib/agent-runtime.ts of 23blocks-OS ai-maestro v0.24.17. An attacker who can send crafted input to the session-kill path can have that input executed as operating-system commands, because the function fails to adequately neutralize special command characters before use. Successful exploitation yields arbitrary command execution with the privileges of the ai-maestro process, with high impact to confidentiality, integrity, and availability, reflected in the critical CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges or user interaction required). The available data identifies only v0.24.17 as affected, and no fixed version or broader affected range is specified. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates a roughly 1.6% (74th percentile) probability of exploitation within 30 days.

What to do: Upgrade 23blocks-OS ai-maestro beyond v0.24.17 as soon as the vendor publishes a patched release, and monitor the vendor's advisories since no fixed version is named in the current data. Until patched, restrict network access to hosts running ai-maestro (the vector is unauthenticated over the network) and review whether untrusted input can reach the killSessionSync/session-kill functionality. Given no known exploitation, standard patch prioritization applies, but do not defer remediation if the component is internet-reachable.

Affected
23blocks-OS ai-maestrov0.24.17 (only version listed in the data; no fixed version or other affected ranges specified)
Estimated exposure
nicheunknown; plausibly on the order of hundreds to a few thousand installations (low-confidence estimate) — No public install, download, or internet-exposure counts were provided; the affected release is an early 0.x-stage component with no signals of broad deployment, so the install base is assumed to be small.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.