Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-85672: zerox 1.1.20 allows attackers to run commands via crafted URLs

CVE-2026-85672 · published today
Summary

The zerox version 1.1.20 program can be tricked into executing any command on the server when it processes a specially crafted document link. This could let an attacker take control of the system or steal data. Apply the vendor's update or patch and ensure that any file‑handling code validates and sanitizes input before using it in system commands.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
getomni-ai zerox <= 1.1.20
Original advisory text
zerox 1.1.20 OS Command Injection via Document URL File Extension
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-78OS Command Injection
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85672 · MITRE
Monitor software like this
Free during beta