← Back to browse · API

CVE-2026-26833

Severity
CRITICAL
CVSS
9.8
EPSS
0.02308
Risk score
40.01
CISA KEV
No
PoC
Yes
Published
2026-03-25
Modified
2026-03-28
First seen
2026-08-07
Aliases
EUVD-2026-15463, GHSA-MVHF-547C-H55R
Products
n/a:n/a n/a
Sources
euvd EUVD-2026-15463
packetstorm 6d0c33a75c67ee0fb36e4a33|CVE-2026-26833

Description

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

References