Skip to main content
E
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
GitHub Security Advisories
›
GHSA-qr28-p3wr-mxq3
GHSA-qr28-p3wr-mxq3
High
CVSS
8.8
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
Vendor
GitHub Security Advisories
Published
May 18, 2026
Last Modified
May 18, 2026
🔗 CVE IDs covered (1)
CVE-2025-57282 →
📋 Description
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
🔗 References (4)
https://nvd.nist.gov/vuln/detail/CVE-2025-57282
https://gist.github.com/Dremig/90c2a0a2f85b0921f10e0bb3192a0c23
https://www.npmjs.com
https://github.com/advisories/GHSA-qr28-p3wr-mxq3