OS Command Injection Vulnerability in FoundDream Miniclawd
CVE-2026-9452
Key Information:
- Vendor
Founddream
- Status
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9452?
A security vulnerability exists in FoundDream miniclawd, specifically in the ExecTool.execute function within the exec.ts file. This issue allows for OS command injection, enabling an attacker to execute arbitrary commands on the server remotely. Although the vulnerability has been publicly disclosed, the lack of versioning for the product complicates the identification of affected releases. The FoundDream team was notified of the issue but has yet to respond to the report or provide updates regarding mitigation.
Affected Version(s)
miniclawd 2d65665046e2222eeea76cafc8570ed546a8c125
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
