Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-37751: 23blocks-OS ai-maestro lets attackers run commands
CVE-2026-37751 · published 6 days ago
Summary
The ai‑maestro software version 0.24.17 contains a flaw in a function that handles session termination. An attacker who can send specially crafted data could cause the system to run any operating‑system command they choose, potentially taking control of the server. Update to the latest release or apply the vendor’s recommended patch and ensure all input is properly sanitized.
Original advisory text
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
Severity
9.8
Critical
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Sources
CVE-2026-37751 · NVD
Monitor software like this
Free during beta