Skip to content
Threat Feed
high advisory

Remote Command Injection in HKUDS AnyTool Execute Endpoint

HKUDS AnyTool version 0.1.0 is vulnerable to remote OS command injection via the Execute Endpoint component, allowing unauthenticated attackers to execute arbitrary system commands.

CVE search metadata

CVE search record: CVE-2026-102874. Severity: high. CVSS: 7.3. KEV: no. Product: AnyTool (0.1.0). Brief: Remote Command Injection in HKUDS AnyTool Execute Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102874/

A remote command injection vulnerability exists in HKUDS AnyTool version 0.1.0, specifically within the anytool/local_server/main.py file. The vulnerability resides in the Execute Endpoint component's use of the subprocess.run function. By manipulating the command or shell arguments passed to this function, an unauthenticated remote attacker can achieve arbitrary OS command execution on the host running the AnyTool server.

The vulnerability is publicly disclosed, and proof-of-concept exploit code is circulating. As of the time of reporting, the vendor has not released a patch or responded to the issue, leaving deployments exposed to exploitation. This flaw is particularly critical for organizations using the local server component of AnyTool in internet-facing configurations, as it provides a direct vector for initial access and execution without requiring prior authentication.

Impact

Successful exploitation allows for full system compromise, including unauthorized access to data, lateral movement within the network, and the deployment of additional malicious payloads. All organizations currently running HKUDS AnyTool 0.1.0 are at risk of remote exploitation. Given the availability of public exploits, the probability of targeted attacks against exposed instances is high.

Recommendation

Prioritized, concrete actions for security operations and IT teams:

  • Disable or firewall off the HKUDS AnyTool local server component until a patched version is available from the vendor.
  • Scan the network for instances of AnyTool 0.1.0 that are exposed to the public internet using external-facing vulnerability scanners.
  • Monitor logs for unusual process spawning originating from the user account or directory where the AnyTool server is executing.
  • Review the integrity of the anytool/local_server/main.py file on identified hosts to detect any unauthorized modifications.

Immediate actions

Isolate systems running HKUDS AnyTool 0.1.0 from the public internet.

IT Operations 24h

Mitigations

Disable the local server component of AnyTool 0.1.0.

immediate IT Operations

CVE-2026-102874