CVE-2026-28673 | danvei233 xiaoheiFS up to 0.3.x ZIP File Parser manifest.json binaries os command injection (GHSA-4vw4-5wmh-7x4v)
A vulnerability was found in danvei233 xiaoheiFS up to 0.3.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manifest.json of the component ZIP File Parser. Executing a manipulation of the argument binaries can lead to os command injection.
This vulnerability is handled as CVE-2026-28673. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.