OurCVEs
Register
Back to feed
High
GHSA-wc3f-xc32-435f
(CVE-2026-55173)

Published Jun 23, 2026

CVSS

8.1

HIGH

EPSS

Exploit Prediction Scoring System — the modeled probability of in-the-wild exploitation in the next 30 days.

Affected packages

0
Summary

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Developer impact

Recommended action

Affected packages
Sources