---
id: CVE-2026-51857
title: >-
  In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can
  run model-produced Python code through SubprocessInterpreter without an
  approval boundary.
summary: >-
  In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can
  run model-produced Python code through SubprocessInterpreter without an
  approval boundary.
severity: none
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:17:11.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51857'
references:
  - url: 'https://gist.github.com/Ro1ME/78606e0763520d6519897e90b305d3cd'
    label: cve@mitre.org
  - url: 'https://github.com/camel-ai/camel/issues/4037'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T21:25:07.842Z'
---

## Overview

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
