GHSA-hhjv-jq77-cmvx
### Summary [zeptoclaw](https://github.com/qhkm/zeptoclaw) implements a [blocklist](https://github.com/qhkm/zeptoclaw/blob/fe2ef07cfec5bb46b42cdd65f52b9230c03e9270/src/tools/android/actions.rs#L413-L424) to prevent dangerous commands running in android device shell, but this blocklist has several blocked commands with argements in the pattern literal, such as `rm -f` and `rm -rf`, this can be simply bypassed by using different orders for these arguments, such as `rm -r -f` or `rm -fr` etc. ### Details As in code [src/tools/android/actions.rs#L413-L424](https://github.com/qhkm/zeptoclaw/blob/fe2ef07cfec5bb46b42cdd65f52b9230c03e9270/src/tools/android/actions.rs#L413-L424), we can see the `rm -f` and `rm -rf` are hard coded and thus can be simply bypassed via `rm -r -f` or `rm -fr` etc. ```rust pub async fn device_shell(adb: &AdbExecutor, cmd: &str) -> Result<String> { // Normalize whitespace for blocklist check let normalized: String = cmd.split_whitespace().collect::<Vec<_>>().join(" "); let lower = normalized.to_lowercase(); let blocked = [ "rm -rf", "rm -r", "reboot", "factory_reset", "wipe", "format", "dd if=", "mkfs", "flash", "fastboot", ]; for pattern in &blocked { if lower.contains(pattern) { return Err(ZeptoError::Tool(format!( "Blocked dangerous command containing '{}'", pattern ))); } } ``` ### PoC Set up [zeptoclaw](https://github.com/qhkm/zeptoclaw) with an Android tool and then run the command `rm -f -r` etc. ### Impact Unauthorized command executed in Android device. ### Credit [@zpbrent](https://github.com/zpbrent)
Properties
- ghsa_id
- GHSA-hhjv-jq77-cmvx
- severity
- high
- summary
- zeptoclaw has Android device shell blocklist bypass via argument permutation
- cvss_score
- 7.5
- cve_id
- GHSA-hhjv-jq77-cmvx
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-03-05T00:35:29Z
- source_url
- https://github.com/advisories/GHSA-hhjv-jq77-cmvx
- ghsa_updated
- 2026-03-05T00:35:31Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph