CVE-2026-76072: The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende
Summary
The Continue CLI (a tool for running AI agents from the command line) uses an incomplete blocklist as its only protection against destructive shell commands when running unattended, meaning it tries to block dangerous commands by listing which ones are unsafe rather than allowing only safe ones. An attacker can bypass this protection through prompt injection (tricking the AI by hiding malicious instructions in content like web pages or files the AI reads), allowing them to delete a user's data by using unblocked commands like recursive deletion of certain directories or tools like shred and wipefs.
Vulnerability Details
7.4(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
network
high
none
none
August 24, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76072
First tracked: August 24, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 85%