CVE
CVE-2026-37281
An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.
Exploitation IoCs 10
Domain huggingface[.]co
Domain jfrog[.]com
Filename exploit.hdf5
Filename malicious_jinja.py
GitHub Repo huggingface/hub
GitHub Repo huggingface/transformers
GitHub User PHASEONE[big]
Package @ctx/nightly-build
Package left-pad
Package left-pad@1.0.1