CVE-2026-102874
Received Received - Intake

OS Command Injection in HKUDS AnyTool

Vulnerability report for CVE-2026-102874, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hkuds anytool 0.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated Remote Code Execution (RCE) flaw in HKUDS AnyTool 0.1.0. The issue occurs in the Execute Endpoint where the server directly passes unsanitized user input into a subprocess.run() call without validation. Attackers can send crafted HTTP requests with a command field and shell flag to execute arbitrary OS commands with the server's privileges. The server exposes endpoints like POST /execute and POST /setup/execute without authentication, making it remotely exploitable.

Detection Guidance

To detect this vulnerability, check if AnyTool's local server is running on your system. Look for the Flask server process with the command 'python -m anytool.local_server.main' binding to ports like 5000 or 0.0.0.0. Test the endpoints by sending a crafted HTTP POST request to /execute or /setup/execute with a command payload like {"command": "echo test", "shell": true} and observe if arbitrary commands execute.

  • Check running processes: ps aux | grep 'python -m anytool.local_server.main'
  • Test endpoints: curl -X POST http://localhost:5000/execute -H 'Content-Type: application/json' -d '{"command": "whoami", "shell": true}'
  • Scan network ports: netstat -tulnp | grep 5000
Impact Analysis

This vulnerability allows attackers to execute any operating system command on the server hosting AnyTool. This could lead to full system compromise, data theft, unauthorized access, or installation of malware. Since the server runs with its own privileges, attackers could gain control over the affected machine. The exploit is publicly available and can be triggered remotely without authentication.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized remote access and potential data breaches. GDPR mandates protection of personal data and requires breach notification, while HIPAA requires safeguards for protected health information. The lack of authentication and input validation could result in unauthorized data access or exfiltration, leading to regulatory penalties and legal consequences.

Mitigation Strategies

Immediately disable the AnyTool server if running. Update the application to enforce authentication on all endpoints and set shell=False by default. Restrict server binding to localhost only. Review and sanitize all inputs to prevent command injection. Consider firewall rules to block unauthorized access to the server ports.

  • Stop the server process: pkill -f 'python -m anytool.local_server.main'
  • Update code to disable shell=True and add input validation
  • Bind server to 127.0.0.1 only: change server configuration to localhost binding

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102874. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart