OpenAkita Command Injection Vulnerability in Chat API Endpoint

Vulnerability

A command injection vulnerability has been identified in OpenAkita versions through 1.24.3, specifically within the Chat API Endpoint. The issue arises in the 'run' function of 'src/openakita/tools/shell.py', where improper handling of the 'Message' argument allows for OS command injection. This vulnerability requires local execution to exploit.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution, potentially leading to local privilege escalation if the OpenAkita process has elevated rights.

Reproduction

To reproduce this vulnerability, a local attacker can send a crafted message through the Chat API Endpoint that manipulates the 'Message' argument. This crafted message should include payloads that exploit the command injection flaw, taking advantage of the application's ability to execute shell commands.

Added: Mar 11, 2026, 11:18 PM
Updated: Mar 11, 2026, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.