VYPR

h-ui

by Jonssonyan

CVEs (1)

  • CVE-2026-107202Oct 7, 2026
    risk 0.00cvss —epss —

    A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs…