CVE-2026-25807
中文标题:
(暂无数据)
英文标题:
Unauthenticated Remote Code Execution via P2P Sharing in ZAI-Shell
漏洞描述
中文描述:
(暂无数据)
英文描述:
ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this port using a simple socket script. An attacker who connects to a ZAI-Shell P2P session running in --no-ai mode can send arbitrary system commands. If the host user approves the command without reviewing its contents, the command executes directly with the user's privileges, bypassing all Sentinel safety checks. This vulnerability is fixed in 9.0.3.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| TaklaXBR | zai-shell | < 9.0.3 | - | - |
cpe:2.3:a:taklaxbr:zai-shell:<_9.0.3:*:*:*:*:*:*:*
|
| taklaxbr | zai_shell | * | - | - |
cpe:2.3:a:taklaxbr:zai_shell:*:*:*:*:*:python:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-25807 |
2026-02-10 03:20:01 | 2026-02-09 22:00:04 |
| NVD | nvd_CVE-2026-25807 |
2026-02-10 02:00:05 | 2026-02-09 22:00:06 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 1 -> 2
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']