CVE-2026-30631
Received Received - Intake

Arbitrary Code Execution in bytebot-ai

Vulnerability report for CVE-2026-30631, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: MITRE

Description

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bytebot-ai bytebot-ai *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows attackers to execute arbitrary code by exploiting a crafted path in the computer_write_file function of bytebot-ai. The issue was discovered in a specific commit from 2025-09-11.

Impact Analysis

Attackers could exploit this to run malicious code on affected systems, potentially leading to unauthorized access, data theft, or system compromise. The impact depends on how bytebot-ai is used in your environment.

Mitigation Strategies

Immediately update bytebot-ai to a patched version if available. Remove or restrict access to the computer_write_file function if not needed. Monitor for unusual file writes or code execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-30631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart