CVE-2026-8235 MEDIUM

CVE-2026-8235: 8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection

Vendor 8421Bit
Product MiniClaw
Weakness CWE-78
Published May 10, 2026
Last update May 11, 2026

CVSS base score

5.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The exploit is now public and may be used. The patch is identified as 223c16a1088e138838dcbd18cd65a37c35ac5a84. It is best practice to apply a patch to resolve this issue.

Key dates

02Disclosure timeline

May 10, 2026 CVE published
May 11, 2026 Record updated