Loading market data...
← Back to CVE feed

CVE-2026-37281

UNKNOWN View on NVD ↗

Description

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

Published: May 19, 2026 16:16 UTC Modified: May 19, 2026 18:04 UTC