PT-2026-67513 · Undefined · Undefined

CVE-2026-51190

·

Published

2026-08-03

·

Updated

2026-08-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-51190

Affected Products

Undefined