CVE-2026-2544

A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-16 08:16

Updated : 2026-02-18 17:52


NVD link : CVE-2026-2544

Mitre link : CVE-2026-2544

CVE.ORG link : CVE-2026-2544


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')