CVE-2026-72580 | duhow xiaoai-patch Endpoint api/main.py os.system silent os command injection (fb07049)
A vulnerability was found in duhow xiaoai-patch. It has been classified as critical. Affected by this issue is the function os.system of the file api/main.py of the component Endpoint Handler. Performing a manipulation of the argument silent results in os command injection.
This vulnerability is cataloged as CVE-2026-72580. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More