CVE-2026-25130 | aliasrobotics cai up to 0.5.10 subprocess.Popen args os command injection (GHSA-jfpc-wj3m-qw2m / EUVD-2026-5008)
A vulnerability identified as critical has been detected in aliasrobotics cai up to 0.5.10. Affected by this vulnerability is the function subprocess.Popen. The manipulation of the argument args leads to os command injection.
This vulnerability is documented as CVE-2026-25130. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.