---
id: CVE-2026-107202
title: >-
  A command injection vulnerability exists in the h-ui (version v0.0.25 and
  below) administrative API due to improper validation of the listen
  configuration field
summary: >-
  A command injection vulnerability exists in the h-ui (version v0.0.25 and
  below) administrative API due to improper validation of the listen
  configuration field. When an authenticated administrator submits a value
  containing shell metach…
severity: none
cwe:
  - CWE-78
vendor: jonssonyan
product: h-ui
affected:
  - h-ui 0.0.25
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:02:48.300'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107202'
references:
  - url: 'https://github.com/jonssonyan/h-ui'
    label: cret@cert.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T15:36:04.055Z'
---

## Overview

A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
