OS Command Injection Vulnerability in zerox by GetOmni-AI
CVE-2026-85672

9.3CRITICAL

Key Information:

Vendor

Getomni-ai

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85672?

The zerox 1.1.20 version is vulnerable to an OS command injection, primarily stemming from the way it handles temporary file extensions derived from document URLs. This vulnerability allows attackers to exploit the file download mechanism by submitting crafted document URLs that incorporate malicious file extensions embedded with command substitution syntax. Consequently, when the system processes these URLs, it may execute arbitrary OS commands through the utilities engaged in document handling. This flaw poses a significant risk to systems utilizing zerox, as unauthorized commands can be executed prior to the document processing phase.

Affected Version(s)

zerox 0 <= 1.1.20

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.