CRITICAL
Serverless-Devs
CVE published 2026-08-03
CVE-2026-51190
The 's init' command in Serverless-Devs @serverless-devs/s version <= 3.1.11 is vulnerable to OS command injection. This critical vulnerability allows an attacker to execute arbitrary OS commands by providing a URL ending in '.git' as an argument, bypassing the only input check. Serverless-Devs users, developers, and administrators should be aware of this vulnerability and take immediate action to patch t [truncated]