Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 Go

ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function

GHSA-pqhx-w72w-m393 · CVE-2026-39087

Published · Modified

Description

An issue in Ntfy ntfy.sh before v.2.22.0 allows a remote attacker to execute arbitrary code via the parseActions function.

Ready to move

Start Securing

Free, no credit card | First findings in minutes