CVE-2026-9452
📛 CVE Title
FoundDream miniclawd exec.ts ExecTool.execute os command injection
Description
A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulDB
- CVSS severity
- MEDIUM
- CVSS score
- 6.9 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P- Effective score
- 6.9 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-78,CWE-77 - Reserved
- 2026-05-24
- Published
- 2026-05-25 11:00 UTC
- Last updated
- 2026-05-29 17:20 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/9xxx/CVE-2026-9452.json
- Linked Threat
- CVE-2026-9452 — CVE-2026-9452
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-25 11:16:19 UTC
- NVD last modified
- 2026-07-23 11:10:00 UTC
- NVD CVSS v3.1
- 7.3 / 10 HIGH source: cna@vuldb.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 3.4 / 10
- EPSS score
- 0.0138 (probability of exploitation in next 30 days)
- EPSS percentile
- 69.49% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01
NVD / KEV / EPSS data refreshed 2026-08-01 17:06 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-31668 - Assigner
- VulDB
- Published
- May 25, 2026, 11:00:17 AM
- Updated
- May 29, 2026, 5:20:51 PM
- EUVD base score (CVSS 4.0)
-
6.9 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P - EUVD-reported EPSS
- 1.3900
- Vendors
- FoundDream
- Products
-
miniclawd (2d65665046e2222eeea76cafc8570ed546a8c125)
- Aliases
-
GHSA-5pqf-2j34-6h89
ENISA description: A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| FoundDream | miniclawd |
2d65665046e2222eeea76cafc8570ed546a8c125 (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- VDB-365433 | FoundDream miniclawd exec.ts ExecTool.execute os command injection vdb-entrytechnical-description
- VDB-365433 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- Submit #813767 | FoundDream miniclawd 0 OS Command Injection third-party-advisory
- https://github.com/FoundDream/miniclawd/issues/1 exploitissue-tracking
- https://github.com/FoundDream/miniclawd/ product
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/FoundDream/miniclawd/ tenable:github.com
- https://github.com/FoundDream/miniclawd/issues/1 tenable:github.com
- https://nvd.nist.gov/vuln/detail/CVE-2026-9452 tenable:nvd.nist.gov
- https://vuldb.com/submit/813767 tenable:vuldb.com
- https://vuldb.com/vuln/365433 tenable:vuldb.com
- https://vuldb.com/vuln/365433/cti tenable:vuldb.com
- https://www.cve.org/CVERecord?id=CVE-2026-9452 tenable:www.cve.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (5)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/FoundDream/miniclawd/ cna@vuldb.com
- https://github.com/FoundDream/miniclawd/issues/1 cna@vuldb.com
- https://vuldb.com/submit/813767 cna@vuldb.com
- https://vuldb.com/vuln/365433 cna@vuldb.com
- https://vuldb.com/vuln/365433/cti cna@vuldb.com
Remediations (20)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-06-04 00:06 UTC -
web:cybersecuritynews.com
Microsoft has released its April 2026 Patch Tuesday security update, addressing 168 vulnerabilities across its product portfolio including one actively exploited zero-day and one publicly disclosed flaw that organizations must prioritize immediately.
2026-06-04 00:06 UTC -
web:documentation.n-able.com
N-central third-party software patch list The table below lists the third party patches available through Patch Management. The Windows agent communicates with the probe to determine what third-party applications can be updated. The agent obtains a list of applications from the probe and compares it to the software installed on a device. The agent determines what applications on a device need ...
2026-06-04 00:06 UTC -
web:knowledge.broadcom.com
The intent of this article is to help customers that are using VMware vSphere 8.x address the most critical security vulnerabilities. Broadcom will provide all perpetual license customers, including those that have expired support contracts, with access to zero-day security patches, which are defined by Broadcom as patches for Critical Severity Security Alerts with a Common Vulnerability ...
2026-06-04 00:06 UTC -
web:nvd.nist.gov
Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...
2026-06-04 00:06 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:06 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-04 00:06 UTC -
web:www.sammobile.com
Samsung has detailed the May 2026 security patch for Galaxy smartphones, smartwatches, and tablets. It brings two critical security fixes.
2026-06-04 00:06 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-06-04 00:06 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-04 00:06 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-06-19 02:25 UTC -
web:fixtrading.org
FIX standards are open, technology-neutral specifications for electronic trading and trade processing. They enable seamless, reliable communication across the full trade lifecycle from pre‑trade and execution to clearing, settlement and reporting. Developed and maintained by the industry to help firms increase efficiency, reduce cost and risk, and meet evolving regulatory and market ...
2026-06-19 02:25 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:25 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-19 02:25 UTC -
web:officialfixdessertchocolatier.com
Indulge in Dubai's viral chocolate bars with FIX Dessert Chocolatier. Shop our hero collection featuring Baklawa, Knafeh, Biscoff, and more. Fast delivery in Dubai & Abu Dhabi. Order now!
2026-06-19 02:25 UTC -
web:support.apple.com
About the security content of iOS 26.2 and iPadOS 26.2 This document describes the security content of iOS 26.2 and iPadOS 26.2. About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page. Apple ...
2026-06-19 02:25 UTC -
web:support.microsoft.com
Note: The fix for CVE - 2026 -45583 is not included in the Security Update, please follow the instructions mentioned in the CVE documentation to address this vulnerability.
2026-06-19 02:25 UTC -
web:www.golfthepatch.com
Now open, The Patch features a redesigned 18-hole course, led by golf course architects Tom Fazio and Beau Welling, and a new 9-hole short course, The Loop at The Patch , designed by Tiger Woods and TGR Design. Welcome to Augusta's best-in-class public golf experience.
2026-06-19 02:25 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-06-19 02:25 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - January 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical ...
2026-06-19 02:25 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-9452.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-9452",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-29T17:20:16.532273Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-29T17:20:51.340Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:founddream:miniclawd:*:*:*:*:*:*:*:*"
],
"product": "miniclawd",
"vendor": "FoundDream",
"versions": [
{
"status": "affected",
"version": "2d65665046e2222eeea76cafc8570ed546a8c125"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ybdesire (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "OS Command Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "Command Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-25T11:00:17.219Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-365433 | FoundDream miniclawd exec.ts ExecTool.execute os command injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/365433"
},
{
"name": "VDB-365433 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/365433/cti"
},
{
"name": "Submit #813767 | FoundDream miniclawd 0 OS Command Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/813767"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/FoundDream/miniclawd/issues/1"
},
{
"tags": [
"product"
],
"url": "https://github.com/FoundDream/miniclawd/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-05-24T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-05-24T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-05-24T09:59:31.000Z",
"value": "VulDB entry last update"
}
],
"title": "FoundDream miniclawd exec.ts ExecTool.execute os command injection"
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-9452",
"datePublished": "2026-05-25T11:00:17.219Z",
"dateReserved": "2026-05-24T07:54:23.407Z",
"dateUpdated": "2026-05-29T17:20:51.340Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}