GHSA-qr28-p3wr-mxq3HighCVSS 8.8

ngrok is Vulnerable to Command Injection

Published
May 18, 2026
Last Modified
May 29, 2026

🔗 CVE IDs covered (1)

📋 Description

ngrok v4.3.3 and 5.0.0-beta.2 are vulnerable to Command Injection.

🎯 Affected products2

  • npm/ngrok:= 4.3.3
  • npm/ngrok:= 5.0.0-beta.2

🔗 References (4)