PT-2026-41946 · Hitarth Gg · Zenshin

CVE-2026-37281

·

Published

2026-05-19

·

Updated

2026-07-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hitarth-gg Zenshin versions prior to 2.7.0
Description An OS command injection flaw exists in the '/stream-to-vlc' Express route. This allows remote attackers to execute arbitrary commands on the host operating system by manipulating the url parameter.
Recommendations Update to version 2.7.0 or later. As a temporary workaround, restrict access to the '/stream-to-vlc' endpoint or avoid using the url parameter until the update is applied.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-37281

Affected Products

Zenshin