Junglewise Threat Intelligence

CVE-2026-9453: FoundDream miniclawd command injection in SkillsLoader

CVE-2026-9453 · Severity: high · CVSS 7.3 · Published 2026-05-25

Executive brief

FoundDream miniclawd, a lightweight AI assistant, is vulnerable to a security flaw that allows attackers to execute unauthorized commands on the host system. By providing a specially crafted skill file, an attacker can gain control over the server running the assistant, potentially leading to data theft or full system compromise. This is particularly serious as the assistant is designed to handle multi-channel communications like Telegram and Feishu.

Technical details

A command injection vulnerability exists in the `which()` method within `src/application/skills-loader.ts` of FoundDream miniclawd. The application uses `execSync` to execute a shell command constructed by concatenating the `requires.bins` argument from skill metadata without proper sanitization or escaping. An attacker who can provide or influence a malicious `SKILL.md` file can inject arbitrary shell commands (e.g., using semicolons) that execute with the privileges of the application process. While the project was notified via a public issue report, no official patch has been confirmed as of the advisory date.

Affected products

  • FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125

Timeline

  • 2026-04-27: disclosed: Issue reported on GitHub repository
  • 2026-05-25: advisory: VulDB and NVD publication

References

Related threats