A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Yued-fe
Yued-fe lulu Ui
Vendors & Products Yued-fe
Yued-fe lulu Ui

Mon, 16 Feb 2026 07:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipulation results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title yued-fe LuLu UI run.js child_process.exec os command injection
Weaknesses CWE-77
CWE-78
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-02-16T07:32:06.183Z

Updated: 2026-02-16T07:32:06.183Z

Reserved: 2026-02-15T15:54:20.415Z

Link: CVE-2026-2544

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-16T08:16:05.287

Modified: 2026-02-16T08:16:05.287

Link: CVE-2026-2544

cve-icon Redhat

No data.