highCVSS 7.5Vulnerability

GHSA-hhjv-jq77-cmvx

### Summary [zeptoclaw](https://github.com/qhkm/zeptoclaw) implements a [blocklist](https://github.com/qhkm/zeptoclaw/blob/fe2ef07cfec5bb46b42cdd65f52b9230c03e9270/src/tools/android/actions.rs#L413-L424) to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as `rm -f` and `rm -rf`, this can be simply bypassed by using different orders for these arguments, such as `rm -r -f` or `rm -fr` etc. ### Details As in code [src/tools/android/actions.rs#L413-L424](https://github.com/qhkm/zeptoclaw/blob/fe2ef07cfec5bb46b42cdd65f52b9230c03e9270/src/tools/android/actions.rs#L413-L424), we can see the `rm -f` and `rm -rf` are hard coded and thus can be simply bypassed via `rm -r -f` or `rm -fr` etc. ```rust pub async fn device_shell(adb: &AdbExecutor, cmd: &str) -> Result<String> { // Normalize whitespace for blocklist check let normalized: String = cmd.split_whitespace().collect::<Vec<_>>().join(" "); let lower = normalized.to_lowercase(); let blocked = [ "rm -rf", "rm -r", "reboot", "factory_reset", "wipe", "format", "dd if=", "mkfs", "flash", "fastboot", ]; for pattern in &blocked { if lower.contains(pattern) { return Err(ZeptoError::Tool(format!( "Blocked dangerous command containing '{}'", pattern ))); } } ``` ### PoC Set up [zeptoclaw](https://github.com/qhkm/zeptoclaw) with an Android tool and then run the command `rm -f -r` etc. ### Impact Unauthorized command executed in Android device. ### Credit [@zpbrent](https://github.com/zpbrent)

Properties

ghsa_id
GHSA-hhjv-jq77-cmvx
severity
high
summary
zeptoclaw has Android device shell blocklist bypass via argument permutation
cvss_score
7.5
cve_id
GHSA-hhjv-jq77-cmvx
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-03-05T00:35:29Z
source_url
https://github.com/advisories/GHSA-hhjv-jq77-cmvx
ghsa_updated
2026-03-05T00:35:31Z

Related Entities (3)

AFFECTS (1)

[Software]rust/zeptoclaw

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-hhjv-jq77-cmvx (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal