CVE-2026-30352

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

Published 2026-04-27. Last modified 2026-07-05.