In ZAI Shell versions prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP listener on port 5757 without any authentication. A remote attacker can connect to this exposed port and inject arbitrary system commands into an active ZAI Shell P2P session. When the session is running in --no-ai mode, if the host user approves the received command without reviewing its contents, the command is executed with the host user’s privileges, bypassing ZAI Shell “Sentinel” safety checks. The issue is fixed in ZAI Shell 9.0.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
share start), especially in --no-ai mode; restrict network access to TCP/5757 (e.g., host firewall/ACLs, bind to localhost if supported, or segment behind VPN); and ensure operators do not approve incoming commands without verification.Patch, then assume compromise.
share start (see v9.0.3 release and associated fix commit).1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python proof-of-concept exploit script and a short README with references. The script (`CVE-2026-25807.py`) implements an unauthenticated network-based RCE against ZAI-Shell’s P2P sharing feature when started with `share start --no-ai` (aka no_ai_mode). It opens a TCP connection to the target (default port 5757), sends a newline-delimited JSON `hello` message, then sends a JSON `command` message containing an attacker-supplied shell command (default `id; whoami; hostname`). It optionally reads back any response from the socket, but also notes execution may occur on the host terminal with an approval prompt or direct execution depending on configuration. No persistence, privilege escalation, or lateral movement logic is included—this is a direct command-execution PoC with configurable target IP/port/command via CLI arguments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.