Sceawere

Vulnerability Detail

CVE-2026-102874UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HKUDS AnyTool OS Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
HKUDS
Product
AnyTool
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-30T03:16:57.503Z",
  "pubdate": "2026-09-30T03:16:57.503Z",
  "executiveSummary": "HKUDS AnyTool version 0.1.0 is susceptible to an OS command injection vulnerability located within the 'Execute Endpoint' component.\nThe vulnerability resides in the subprocess.run function within 'anytool/local_server/main.py', where unsanitized user input is passed directly to the system shell.\nThis flaw allows a remote, unauthenticated attacker to execute arbitrary system commands with the privileges of the underlying application process.\nThe risk is critical due to the potential for full system compromise, data exfiltration, and unauthorized service manipulation.\nPublicly available exploit code increases the likelihood of active exploitation, especially given the lack of a vendor response to reported issues.",
  "technicalDetails": "The root cause of this vulnerability is the insecure implementation of the 'Execute Endpoint' in 'anytool/local_server/main.py', specifically the usage of 'subprocess.run' without proper sanitization of command-line arguments.\nWhen the 'command' or 'shell' argument is passed from an external request, the application fails to perform input validation or argument escaping, effectively treating user-supplied input as executable shell commands.\nExploitation is achieved by injecting shell metacharacters such as ';', '&', or '|' into the request payload. By appending malicious commands to a legitimate request, an attacker can manipulate the execution flow to bypass intended functionality.\nThe attack flow proceeds as follows: 1) An attacker sends a specially crafted network request to the Execute Endpoint. 2) The input is processed by 'anytool/local_server/main.py'. 3) The 'subprocess.run' function executes the concatenated string in a system shell. 4) The shell interprets the injected metacharacters, executing the attacker's payload in the same context as the AnyTool server.\nBecause the vulnerability is exposed via the 'Execute Endpoint', it is reachable remotely over the network without requiring prior authentication. The impact is significant, as the resulting command execution grants the attacker the same permission set as the AnyTool daemon, facilitating lateral movement or persistence within the environment.\nThis vulnerability is particularly dangerous because the underlying subprocess call often spawns a shell process (e.g., /bin/sh or cmd.exe) if 'shell=True' is set or if the command is passed as a string rather than a list. The absence of input filtering allows for common injection payloads, such as reverse shell spawning, file system traversal, or credential harvesting.\nThe current version 0.1.0 remains unpatched, and the lack of vendor engagement implies that users must implement independent defensive measures to secure their installations."
}
CVE-2026-102874: HKUDS AnyTool OS Command Injection (HIGH Severity, CVSS: 7.3) | Sceawere