CVE-2026-18980: nearai ironclaw shell.rs classify_command_risk command injection
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classifycommandrisk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is a1d7c3ba428ed575900469b207fb5668725f9a71. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nearai/ironclawto a version that resolves this vulnerability.Fixed in 0.29.1Patch a1d7c3ba428ed575900469b207fb5668725f9a71
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18980?
CVE-2026-18980 has a severity rating of medium with a score of 6.3.
How do I fix CVE-2026-18980?
To fix CVE-2026-18980, update nearai ironclaw to version 0.29.2 or later.
What type of vulnerability is CVE-2026-18980?
CVE-2026-18980 is classified as a command injection vulnerability.
Can CVE-2026-18980 be exploited remotely?
Yes, CVE-2026-18980 can be exploited remotely.
What functions are affected by CVE-2026-18980?
CVE-2026-18980 specifically affects the classify_command_risk function in src/tools/builtin/shell.rs.