Junglewise Threat Intelligence

CVE-2026-16129: princezuda SafestClaw command allowlist bypass in ShellAction

CVE-2026-16129 · Severity: medium · CVSS 5.3 · Published 2026-07-18

Executive brief

SafestClaw is an open-source automation tool and AI assistant alternative. A security flaw in its built-in web interface allows users to bypass command restrictions. By using specific command wrappers, an attacker can execute unauthorized programs on the underlying system, potentially leading to full system compromise or unauthorized data access.

Technical details

A vulnerability exists in the `ShellAction._validate_command` function within `src/safestclaw/actions/shell.py`. The validation logic uses `shlex.split()` to tokenize user input but only verifies the first token against an allowlist. Because the `env` utility is included in the default allowlist, an attacker can use it as a wrapper (e.g., `env bash -c <command>`) to execute arbitrary interpreters that are otherwise blocked. The application then passes the full, unvalidated argument array to `asyncio.create_subprocess_exec()`. This allows a local user with access to the web interface to bypass security boundaries and execute arbitrary code with the privileges of the SafestClaw process.

Affected products

  • princezuda SafestClaw <= 4.2.4

Timeline

  • 2026-07-18: disclosed: Vulnerability disclosed via GitHub issue and VulDB
  • 2026-07-18: advisory

References