CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-108751: moai-adk 0 through 3.1.2

Affected technology

moai-adk · 0 through 3.1.2
modu-ai

Description’s affected range: through 3.1.2

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · Passive user interaction

What an attacker can do

Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content. Vendor/CNA’s CVSS 4.0 assessment (base score 4.8/10) rates confidentiality impact as none; integrity and availability impact as low.

Published

CWE
CWE-59
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108751.html