PatchSiren

4xmen CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH 4xmen CVE published 2026-08-10

CVE-2026-72573

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T11:17:30.010Z and has not been modified since then. The CVE-2026-72573 vulnerability is an OS command injection issue in the 4xmen/pm2panel application. The vulnerability exists in the pm2panel.js file at line 188, where the req.query.id parameter is passed directly to the exec('pm2 restart ' + i [truncated]