CVE-2025-57282

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.

Published 2026-05-18. Last modified 2026-06-17.