Command Injection Vulnerability in FoundDream Miniclawd Product
CVE-2026-9453
Key Information:
- Vendor
Founddream
- Status
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9453?
A command injection vulnerability has been identified in FoundDream's miniclawd, particularly within the SkillsLoader component's skills-loader.ts file. The flaw exists when manipulating the 'requires.bins' argument, which may allow attackers to execute arbitrary commands on the server remotely. The exploit for this vulnerability is publicly available, and despite reporting the issue, there has been no response from the project's maintainers. Given that miniclawd employs a rolling release model for updates, specific version details regarding mitigation are currently not obtainable.
Affected Version(s)
miniclawd 2d65665046e2222eeea76cafc8570ed546a8c125
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
