JunoClaw agent platform: shell command injection and SSRF flaws (CVE-2026-43990/43993)
Two vulnerabilities were disclosed in JunoClaw, an agentic AI platform built on Juno Network: plugin-shell's run_command passed agent-supplied argument strings to 'sh -c'/'cmd /C', allowing shell metacharacters to be interpreted as command syntax, and the WAVS bridge's computeDataVerify fetched agent-supplied URLs without validating scheme, port or resolved IP, causing SSRF. Both were fixed in release 0.x.y-security-1.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
Agent-supplied input could be used to execute arbitrary shell command syntax on the host and to make server-side requests to arbitrary URLs/internal addresses in versions prior to 0.x.y-security-1.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43990
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43993
