← Terug naar overzicht

CVE-2026-37751 is an OS command injection vulnerability discovered in the killSessionSync function within lib/agent-runtime.ts of the 23blocks-OS ai-maestro package version 0.24.17. The vulnerability allows remote attackers to execute arbitrary operating system commands by supplying crafted input to the affected function. A fix has been committed to the project's GitHub repository. A security advisory has been published via GitHub's GHSA system, and independent research detailing the remote code execution has been made publicly available. The vulnerability affects AI agent orchestration tooling, which may be deployed in automated or cloud-based environments, raising the severity of potential exploitation. Users of ai-maestro v0.24.17 are advised to apply the patch immediately.

Affected products

  • 23blocks-OS ai-maestro v0.24.17

Related CVE's

  • CVE-2026-37751

Categories

  • Emerging Technologies
  • Supply Chain & Dependencies
  • Web Technologies