CVE-2026-72589
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database file. The POST /import endpoint accepts arbitrary .db files and overwrites the application database without validation.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72589.json, https://github.com/alseambusher/crontab-ui, https://nvd.nist.gov/vuln/detail/CVE-2026-72589, https://github.com/alseambusher/crontab-ui/blob/master/crontab.js