Skip to content
MediumVulnerabilityLLM-specific

VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check

Published
Record updated
View JSON

Summary

CVE-2026-104247 affects vtcode versions below 0.171.5. An empty ANSI-C quote spliced into a find flag (for example -exe$''c) bypasses the is_destructive_find_option check, so the command is still treated as a safe find. Once the agent has learned that find family from three prior approvals, prompt_tool_permission auto-approves it and the shell runs it as the user running VTCode, with no new prompt. Exploitation requires a local session, those prior approvals, and something that can steer the agent, such as indirect prompt injection.

Mitigation

Upgrade to VTCode 0.171.5 or later. Until upgrading, do not rely on learned find approvals. The 0.171.5 release (PR #778, commit 5840697cd0dc8f94b9b53d88185329eecba8de11) refuses family learning for path-qualified find, mixed-case or quote-spliced flags, wrapper and environment prefixes, and compound commands.