CVE-2026-84888

Summary

A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory allocation. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
RightNow-AIOpenFang0.6.0affected
RightNow-AIOpenFang0.6.1affected
RightNow-AIOpenFang0.6.2affected
RightNow-AIOpenFang0.6.3affected
RightNow-AIOpenFang0.6.4affected
RightNow-AIOpenFang0.6.5affected
RightNow-AIOpenFang0.6.6affected
RightNow-AIOpenFang0.6.7affected
RightNow-AIOpenFang0.6.8affected
RightNow-AIOpenFang0.6.9affected

Weaknesses

  • CWE-789: Uncontrolled Memory Allocation
  • CWE-400: Resource Consumption

References