Junglewise Threat Intelligence

CVE-2026-30631: Bytebot-ai OS command injection in computer_write_file

CVE-2026-30631 · Severity: info · CVSS 10 · Published 2026-07-21

Executive brief

Bytebot-ai, an AI-driven automation tool, contains a critical security flaw that allows attackers to take complete control of the system. By sending a specially crafted file path to the application's file-writing component, an attacker can execute malicious commands with administrative (root) privileges. This could lead to the theft of sensitive data, full system compromise, or use of the server for further attacks.

Technical details

An OS command injection vulnerability (CWE-78) exists in the `computer_write_file` tool of the Bytebot Model Context Protocol (MCP) implementation. The vulnerability stems from the use of `exec()` with string interpolation to execute shell commands (such as `sudo cp` and `sudo chown`) using the user-provided `targetPath` without proper sanitization. An attacker can inject shell metacharacters or command substitution tokens (e.g., backticks or `$()`) into the `path` parameter to execute arbitrary commands. Because these commands are executed via `sudo` within the Docker environment, successful exploitation results in root-level code execution inside the container. This can be triggered via direct network access to the MCP port (default 9990) or indirectly through prompt injection if the tool is exposed to an LLM agent.

Affected products

  • bytebot-ai bytebot-ai commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313

Timeline

  • 2025-09-11: other: Vulnerable commit identified
  • 2026-02-08: disclosed: Proof of concept and technical details shared via GitHub Gist
  • 2026-07-21: advisory: CVE published to NVD

References