CVE-2026-16204

Source
https://cve.org/CVERecord?id=CVE-2026-16204
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16204.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16204
Published
2026-07-19T01:45:11.609Z
Modified
2026-07-23T03:56:20.011209874Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
Details

A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function toolrunscript_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16204.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ]
}
References

Affected packages

Git / github.com/zevorn/rt-claw

Affected ranges

Type
GIT
Repo
https://github.com/zevorn/rt-claw
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.1"
        },
        {
            "last_affected": "0.1"
        },
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1
0.2.0
v0.*
v0.1.0
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16204.json"