CVE-2026-51857: Pypi/camel-ai vulnerability
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
Deployments using camel-ai versions 0.2.91a1, v0.2.91a2, or v0.2.91a3 are exposed when they use CodeExecutionToolkit with SubprocessInterpreter to execute model-produced Python.
An attacker would need to cause the model to produce Python code that reaches CodeExecutionToolkit and is run through SubprocessInterpreter. The affected path has no approval boundary before execution.
Check whether the installed camel-ai version is 0.2.91a1, v0.2.91a2, or v0.2.91a3, and review whether CodeExecutionToolkit is configured to use SubprocessInterpreter. The provided information does not establish whether this configuration is enabled by default.