CVE-2025-4032 is a critical OS command injection vulnerability affecting inclusionAI AWorld up to commit 8c257626e648d98d793dd9a1a950c2af4dd84c4e, specifically within the subprocess.run/Popen function in AWorld/aworld/virtual_environments/terminals/shell_tool.py. This vulnerability carries a CVSS score of 8.1 (High), indicating a significant risk. While the attack can be initiated remotely, its complexity is high, and exploitation is known to be difficult. Although the exploit has been publicly disclosed, there is no evidence of active exploitation, Metasploit, Nuclei, or ExploitDB modules, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-04-24CPE matchmatch criteria | cpe:2.3:a:inclusionai:aworld:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.