{"id":"CVE-2026-51857","title":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.","summary":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.","severity":"none","published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:17:11.647","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51857","references":[{"url":"https://gist.github.com/Ro1ME/78606e0763520d6519897e90b305d3cd","label":"cve@mitre.org"},{"url":"https://github.com/camel-ai/camel/issues/4037","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T21:25:07.842Z","slug":"CVE-2026-51857","body":"## Overview\n\nIn camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}