Skip to content

CVE lookup

CVE-2026-72573

Pruva has a verified reproduction for CVE-2026-72573: Authenticated command injection in pm2panel's /restart handler allows remote shell command execution on the host.. The canonical evidence record is REPRO-2026-00334.

REPRO

REPRO-2026-00334

Package

4xmen/pm2panel · GitHub / Node.js web application

Severity

HIGH

Status

published