Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ai-platform-securityopen-source-dependency-vulnerabilityproof-of-concept-release

Critical Command Injection Vulnerability in Cybersecurity AI (CAI) Framework

Updated 2d agoFirst seen Dec 12, 20253 sources

A critical command injection vulnerability, tracked as CVE-2025-67511, has been identified in the open-source Cybersecurity AI (CAI) framework, which is used for building and deploying AI-powered offensive and defensive automation. The flaw exists in the run_ssh_command_with_credentials() function, where only the password and command inputs are properly escaped, leaving the username, host, and port parameters vulnerable to injection. This allows attackers to craft malicious inputs that can execute arbitrary shell commands via AI agents, potentially compromising affected systems remotely. The vulnerability affects all CAI versions up to and including 0.5.9, and no official fix or patch is available as of the latest reports.

The issue is classified as critical, with a CVSS v3.1 base score of 9.6 or higher, reflecting the high risk to confidentiality, integrity, and availability. Exploitation requires user interaction, likely through the AI agent's command execution interface, but does not require authentication or elevated privileges. Security advisories recommend that organizations using CAI implement compensating controls and monitor for suspicious activity, as the vulnerability is remotely exploitable and no mitigation has been released. The lack of a patch increases the urgency for defensive measures to prevent potential exploitation in production environments.

Share:
Critical Command Injection Vulnerability in Cybersecurity AI (CAI) Framework
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Dec 11, 20257mo ago

Technical advisories and PoC details published for CVE-2025-67511

By the time of public publication, security advisories and technical details, including GitHub proof-of-concept exploit information, had been made available by researchers and referenced by vendors. The disclosures emphasized the vulnerability's critical severity, remote exploitability, and the absence of an official patch.

Dec 10, 20257mo ago

CVE-2025-67511 disclosed in Alias Robotics CAI

A critical command injection vulnerability, CVE-2025-67511, was disclosed in Cybersecurity AI (CAI) versions 0.5.9 and below. The flaw affects the run_ssh_command_with_credentials() function, where unsanitized username, host, and port parameters can enable remote command execution.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
2 linked
Cybersecurity AI (CAI)Alias Robotics
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Command Injection Vulnerability in Cybersecurity AI (CAI) Framework | Mallory