๐Ÿ” CVE Alert

CVE-2026-26833

CRITICAL 9.8
CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
32th

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

Vendor n/a
Product n/a
Published Mar 25, 2026
Last Updated Mar 28, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new critical vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mmahrous/thumbler npmjs.com: https://www.npmjs.com/package/thumbler github.com: https://github.com/mmahrous/thumbler/blob/master/lib/thumbler.js github.com: https://github.com/zebbernCVE/CVE-2026-26833