CVE-2026-30303
Last modified
CVE-2026-30303 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform, coupled with a failure to correctly handle Windows CMD-specific escape sequences (^). EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windows platform, coupled with a failure to correctly handle Windows CMD-specific escape sequences (^). Attackers can exploit this discrepancy between the parsing logic and the execution environment by constructing payloads such as git log ^" & malicious_command ^". The Axon Code parser is deceived by the escape characters, misinterpreting the malicious command connector (&) as being within a protected string argument and thus auto-approving the command. However, the underlying Windows CMD interpreter ignores the escaped quotes, parsing and executing the subsequent malicious command directly. This allows attackers to achieve arbitrary Remote Code Execution (RCE) after bypassing what appears to be a legitimate Git whitelist check.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matterai | Axon Code | <= 4.123.1 |
References
- https://www.matterai.so/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30303?
How severe is CVE-2026-30303?
How do I fix CVE-2026-30303?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30289An arbitrary file overwrite vulnerability in Tinybeans Priva…8.4
- CVE-2026-3029A path traversal and arbitrary file write vulnerability exis…7.5
- CVE-2026-30290An arbitrary file overwrite vulnerability in InTouch Contact…8.4
- CVE-2026-30291An arbitrary file overwrite vulnerability in Ora Tools PDF R…8.4
- CVE-2026-30292An arbitrary file overwrite vulnerability in Docudepot PDF R…8.4
- CVE-2026-30302The command auto-approval module in CodeRider-Kilo contains …10
- CVE-2026-30304In its design for automatic terminal command execution, AI C…9.6
- CVE-2026-30305Syntx's command auto-approval module contains a critical OS …9.8
- CVE-2026-30306In its design for automatic terminal command execution, Saka…9.8
- CVE-2026-30307Roo Code's command auto-approval module contains a critical …9.8
- CVE-2026-30308In its design for automatic terminal command execution, HAI …9.8
- CVE-2026-30309InfCode's terminal auto-execution module contains a critical…7.8
Are you affected by CVE-2026-30303?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
