CRITICAL 9.8 Go
ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
GHSA-pqhx-w72w-m393 · CVE-2026-39087
Published · Modified
Description
An issue in Ntfy ntfy.sh before v.2.22.0 allows a remote attacker to execute arbitrary code via the parseActions function.
Ready to move
Start Securing
Free, no credit card | First findings in minutes