VYPR

ironclaw

by Nearai

CVEs (2)

  • CVE-2026-18980MedAug 6, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might…

  • CVE-2026-16130MedJul 18, 2026
    risk 0.00cvss 4.4epss 0.00

    A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required to approach this attack.…