Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-51190

AI Predicted 7.2 Difficulty: Easy
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-51190

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled argument.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2026-51190

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51190

登录查看更多情报信息。

Proof of Concept for CVE-2026-51190 (1)

Same Patch Batch · n/a · 2026-08-03 · 20 CVEs total

CVE-2026-185924.7 MEDIUMosCommerce Email Template Configuration EmailController.php EmailController sql injection
CVE-2026-186823.1 LOWOpenAkita File Upload API upload cross site scripting
CVE-2026-67978NASA cFS v7.0.1 SBN接口拒绝服务漏洞
CVE-2026-67673OreSat Firmware v1.0 edl函数栈溢出漏洞
CVE-2026-67975NASA cFS v7.0.1越权操作漏洞
CVE-2026-67974NASA cFS v7.0.1 SBN应用DoS漏洞
CVE-2026-67970NASA cFS v7.0.1路径穿越致敏感组件被访问
CVE-2026-67977fprime v4.2.2 Svc::FileDownlink 整数溢出导致DoS
CVE-2026-67973NASA cFS v7.0.1 CFDP接收路径拒绝服务漏洞
CVE-2026-67969NASA cFS v7.0.1 HS_MonitorApplications远程代码执行漏洞
CVE-2026-51775Fastadmin 1.6.1 SQL注入漏洞
CVE-2026-67976fprime v4.2.2 Ref::SignalGen DoS漏洞
CVE-2026-67972NASA cFS v7.0.1 CFDP信息泄露漏洞
CVE-2026-52102OpenMediaVault v8.0.4-1 openmediavault-md 命令注入漏洞
CVE-2026-52521Z-BlogPHP 1.7.5 评论功能 SQL 注入漏洞
CVE-2026-52520Emlog<=2.6.14后台发布文章存储型XSS漏洞
CVE-2026-38446osTicket 1.18.3存储型XSS漏洞
CVE-2026-38444osTicket v1.18.3 存储型XSS漏洞
CVE-2026-38447osTicket 1.18.3 API密钥生成存在预测性漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51190

No comments yet


Leave a comment