CVE-2026-51857: n/a
In camel-ai versions 0.2.91a1, 0.2.91a2, and 0.2.91a3, the CodeExecutionToolkit component can execute Python code generated by models through the SubprocessInterpreter without an approval boundary. This behavior may allow unapproved or unsafe code execution within these specific versions.
AI Analysis
Technical Summary
CVE-2026-51857 identifies a vulnerability in camel-ai versions 0.2.91a1, 0.2.91a2, and 0.2.91a3 where the CodeExecutionToolkit runs model-produced Python code via SubprocessInterpreter without enforcing an approval boundary. This lack of an approval mechanism means that potentially unsafe or malicious code generated by the model could be executed without restriction.
Potential Impact
The vulnerability allows execution of Python code produced by the model without an approval boundary, which could lead to unauthorized code execution within the affected versions of camel-ai. No specific exploitation details or active exploits in the wild are reported.
Mitigation Recommendations
No patch or official remediation information is provided. Users should review the vendor advisory for updates. Until a fix is available, avoid using the affected versions or restrict usage of the CodeExecutionToolkit to trusted code only.
CVE-2026-51857: n/a
Description
In camel-ai versions 0.2.91a1, 0.2.91a2, and 0.2.91a3, the CodeExecutionToolkit component can execute Python code generated by models through the SubprocessInterpreter without an approval boundary. This behavior may allow unapproved or unsafe code execution within these specific versions.
Affected software
pkg:pypi/camel-ai/camelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-51857 identifies a vulnerability in camel-ai versions 0.2.91a1, 0.2.91a2, and 0.2.91a3 where the CodeExecutionToolkit runs model-produced Python code via SubprocessInterpreter without enforcing an approval boundary. This lack of an approval mechanism means that potentially unsafe or malicious code generated by the model could be executed without restriction.
Potential Impact
The vulnerability allows execution of Python code produced by the model without an approval boundary, which could lead to unauthorized code execution within the affected versions of camel-ai. No specific exploitation details or active exploits in the wild are reported.
Mitigation Recommendations
No patch or official remediation information is provided. Users should review the vendor advisory for updates. Until a fix is available, avoid using the affected versions or restrict usage of the CodeExecutionToolkit to trusted code only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6abd79352a4e24523d9783c6
Added to database: 09/30/2026, 21:03:49 UTC
Last enriched: 09/30/2026, 21:18:58 UTC
Last updated: 10/01/2026, 04:58:25 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.