CVE-2026-31862 | siteboon claudecodeui up to 1.23.x API Endpoint execAsync os command injection (GHSA-f2fc-vc88-6w7q)
A vulnerability was found in siteboon claudecodeui up to 1.23.x. It has been classified as critical. This affects the function execAsync of the component API Endpoint. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-31862. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.