CVE-2026-25933 | arduino arduino-app-lab up to 0.3.x Terminal _info.Serial/_info.Address os command injection (GHSA-3652-939f-f7g4)
A vulnerability was found in arduino arduino-app-lab up to 0.3.x. It has been classified as critical. This issue affects some unknown processing of the component Terminal Component. The manipulation of the argument _info.Serial/_info.Address leads to os command injection.
This vulnerability is listed as CVE-2026-25933. It is possible to launch the attack on the physical device. There is no available exploit.
Upgrading the affected component is recommended.