CVE-2026-37751: Command Injection
Published Aug 28, 2026
·Updated
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
Affected Software
1 affected component
23blocks-OS ai-maestro=0.24.17
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description