ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
Loading...
Loading...
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2026-05-18. NVD baseline CVSS 8.8; sources differ by 0.0.
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
May 18, 2026
May 18, 2026
These vendors published their own advisory mentioning this CVE โ often with vendor-specific remediation steps + affected product lists not in NVD.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-57282
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.