Command Injection Vulnerability in h-ui Administrative API
CVE-2026-107202
Currently unrated
What is CVE-2026-107202?
An authenticated administrator can exploit a command injection vulnerability in the h-ui administrative API by providing malicious input in the listen configuration field. Due to insufficient validation, the application generates iptables/nftables rule strings which are executed as root, allowing the execution of arbitrary operating system commands. This vulnerability underscores the critical need for stringent input validation to prevent unauthorized command execution within administrative components.
Affected Version(s)
h-ui 0.0.25
