External risk intelligence

Camel AI Prompt Injection Executes Shell Commands

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51858

The vulnerability exists in a library designed for agentic AI workflows. While these tools can be integrated into internet-facing applications or APIs, the component itself is a development toolkit rather than a dedicated edge gateway, VPN, or inherently public-facing service. Exposure depends entirely on how a developer integrates the toolkit into their specific application architecture.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in a development toolkit used for AI agent workflows. The issue allows for the execution of commands without proper oversight, which could potentially impact systems if the toolkit is integrated into internet-facing applications. The primary concern at this stage is to determine if this technology is in use within our environment.

  • Commands can run without approval.
  • Critical flaws warrant leadership awareness.
  • Confirm use; assess potential risk.

Attack Path

How an attacker could exploit the issue

An attacker with network access could leverage the `TerminalToolkit.shell_exec` function within the camel-ai camel library to execute arbitrary shell commands. This occurs because the function allows prompt-driven command execution without an approval boundary, meaning user input can directly translate into executable commands. The vulnerability could lead to unauthorized command execution, potentially resulting in system compromise.

  • Entry condition: Network access.
  • Trigger point: Prompt-driven `shell_exec`.
  • Resulting risk: Arbitrary shell command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated user to execute arbitrary shell commands by providing specially crafted prompts when the camel-ai camel tool is integrated into an application that exposes its prompt-driven command execution feature to the network. This could potentially lead to unauthorized access and modification of the underlying system.

  • Arbitrary shell command execution.
  • Network-accessible prompt input.
  • System compromise and data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

The camel-ai camel library's vulnerability in prompt-driven shell command execution requires immediate attention from teams managing AI agent workflows and their integration into applications. The first practical step is to identify all instances of the affected camel versions, confirm their exposure and business criticality, and then determine the accountable owner for remediation planning.

  • AI platform and application owners should address.
  • Verify prompt-driven command execution exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is camel-ai camel?

Camel-ai camel is a software library specifically designed to help developers build and manage agentic AI workflows. These agents use tools to perform tasks, and the library provides components like the TerminalToolkit to facilitate interactions between the AI and the underlying system environment.

What does CWE-94 mean for CVE-2026-51858?

CWE-94 refers to Improper Control of Generation of Code. In the context of this CVE, it means the software allows user-provided input, such as a prompt, to be interpreted as code or shell commands. Because the system lacks an approval boundary, it runs these commands directly without validating the intent, leading to arbitrary command execution.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted prompt to an application that utilizes the affected TerminalToolkit.shell_exec function. The bug is specifically tied to this function; the vulnerability is not triggered by standard usage of the library that does not involve prompt-driven shell command execution.

Is my system at risk if I use this library?

According to Halo Surface Signal, risk depends on your application architecture. The library is a development toolkit, not an edge service, so you are most at risk if you have integrated these AI agent workflows into internet-facing applications or APIs where untrusted users can influence the prompt input.

What should I do if I use the affected camel versions?

Your first step is to locate all applications in your environment that include the affected versions of the camel library. Once identified, evaluate whether those applications expose the prompt-driven command execution feature to network-based input, then coordinate with the accountable application owners to prioritize remediation.

References