Skip to content

Instantly share code, notes, and snippets.

@Garithe
Garithe / CVE-2025-70826.md
Created May 3, 2026 16:33
CVE-2025-70826: Command Restriction Bypass in Arrakis

Public Disclosure: CVE-2025-70826

Vulnerability Summary

A protection mechanism failure exists in the Arrakis project that allows for a command restriction bypass. The system fails to properly validate or sanitize inputs processed through its AI-integrated components, leading to the execution of restricted commands.

Technical Details

  • CVE ID: CVE-2025-70826
  • Affected Product: abshkbh/arrakis
  • Affected Versions: 877231496acbf3b3091ab33340d2d126a251c4d5
  • Vulnerability Type: CWE-693: Protection Mechanism Failure