CVE-2026-37281
the affected product
An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.
- CVSS
- 9.8
- EPSS
- 1.62% 73.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.20