CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-37281

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
1.62%
74th pct
KEV
No
Class
oss containerizable
CWE-78

Description

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

References

Status: profiled · ingested 2026-07-24T18:00:18.000Z