CVE-2026-107202 | jonssonyan h-ui up to 0.0.25 Administrative API fmt.Sprintf listen os command injection
A vulnerability, which was classified as very critical, has been found in jonssonyan h-ui up to 0.0.25. This impacts the function fmt.Sprintf of the component Administrative API. Performing a manipulation of the argument Lists results in os command injection.
This vulnerability is reported as CVE-2026-107202. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More