PT-2026-67513 · Undefined · Undefined
CVE-2026-51190
·
Published
2026-08-03
·
Updated
2026-08-03
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined