CVE-2026-39862 | Shopify tophat up to 2.5.0 URL Parser /bin/bash os command injection (GHSA-8x8g-6rv5-mgg2)
A vulnerability identified as critical has been detected in Shopify tophat up to 2.5.0. This vulnerability affects unknown code of the file /bin/bash of the component URL Parser. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-39862. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.