{"id":"CVE-2026-107202","title":"A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field","summary":"A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metach…","severity":"none","cwe":["CWE-78"],"vendor":"jonssonyan","product":"h-ui","affected":["h-ui 0.0.25"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:02:48.300","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107202","references":[{"url":"https://github.com/jonssonyan/h-ui","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T15:36:04.055Z","slug":"CVE-2026-107202","body":"## Overview\n\nA command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}