haojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injection
Published May 26, 2026
5.3
MEDIUMCVSS 4.0
EPSS 1.77%
Description
A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
Affected
- 0.6.0
- 0.6.1
- 0.6.2
- 0.6.3
- 0.6.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Haojing8312 | WorkClaw | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31886 Advisory
- https://github.com/haojing8312/WorkClaw/ product
- https://github.com/haojing8312/WorkClaw/issues/4 exploitissue-tracking
- https://vuldb.com/submit/815713 third-party-advisory
- https://vuldb.com/vuln/365627 vdb-entrytechnical-description
- https://vuldb.com/vuln/365627/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31886 | Advisory | |
| https://github.com/haojing8312/WorkClaw/ | product | |
| https://github.com/haojing8312/WorkClaw/issues/4 | exploitissue-tracking | |
| https://vuldb.com/submit/815713 | third-party-advisory | |
| https://vuldb.com/vuln/365627 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/365627/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data