Junglewise Threat Intelligence

CVE-2026-30310: Sixth prompt injection and command execution in terminal auto-execution

CVE-2026-30310 · Severity: critical · CVSS 9.8 · Published 2026-03-31

Executive brief

Sixth, an AI-powered terminal tool, contains a vulnerability that allows malicious commands to run automatically without user permission. While the software is designed to ask for approval before running dangerous commands, attackers can use specifically crafted text to trick the AI into thinking a harmful command is safe. This could allow an attacker to take complete control of a user's system, leading to data theft or permanent damage to the operating environment.

Technical details

Sixth (up to version 0.0.68) is vulnerable to OS command injection (CWE-77/CWE-78) due to a flaw in its 'Execute safe commands' validation logic. The tool uses an LLM-based classifier to determine if a terminal command is safe for automatic execution or requires user intervention. An attacker can utilize prompt injection techniques to wrap malicious payloads in templates that mislead the model into misclassifying destructive commands as safe. This bypasses the user approval requirement, leading to remote code execution (RCE) in the context of the terminal user.

Affected products

  • Sixth Sixth <= 0.0.68

Timeline

  • 2026-03-27: disclosed: Vulnerability reported by Secsys-FDU on GitHub.
  • 2026-03-31: advisory: CVE-2026-30310 published.

References