OS Command Injection Vulnerability in zerox by GetOmni-AI
CVE-2026-85672
9.3CRITICAL
What is CVE-2026-85672?
The zerox 1.1.20 version is vulnerable to an OS command injection, primarily stemming from the way it handles temporary file extensions derived from document URLs. This vulnerability allows attackers to exploit the file download mechanism by submitting crafted document URLs that incorporate malicious file extensions embedded with command substitution syntax. Consequently, when the system processes these URLs, it may execute arbitrary OS commands through the utilities engaged in document handling. This flaw poses a significant risk to systems utilizing zerox, as unauthorized commands can be executed prior to the document processing phase.
Affected Version(s)
zerox 0 <= 1.1.20
