Executive brief
ai-maestro is an AI agent orchestration platform that manages multiple coding agents with persistent memory and inter-agent messaging. An OS command injection vulnerability in the session management function allows unauthenticated attackers to execute arbitrary system commands on the host running ai-maestro, potentially leading to complete system compromise.
Technical details
The killSessionSync function in lib/agent-runtime.ts uses execSync() to execute shell commands with unsanitized agent names, allowing shell metacharacter injection. An attacker can craft a malicious agent name containing shell metacharacters (e.g., backticks, pipes) via the POST /api/agents endpoint to inject and execute arbitrary OS commands. The vulnerability requires network access to the ai-maestro API but no authentication. The fix, released in v0.24.18, replaces execSync with execFileSync and adds input validation to restrict agent names to safe characters only.
Affected products
- 23blocks-OS ai-maestro v0.24.17 and earlier
Timeline
- 2026-08-28: disclosed
- 2026-03-09: patched: Fix released in v0.24.18