


Perceptive Security
SOC/SIEM Consultancy

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code vi…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 20:01:57
Source:
nvd.nist.gov
Web Technologies
A remote code execution vulnerability exists in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a. The vulnerability allows attackers to execute arbitrary code by providing a crafted command parameter. This represents a critical security flaw that could allow complete system compromise. The vulnerability affects the development server functionality of the autocoder application. Attackers can exploit this flaw remotely without authentication requirements.
Technical details
Mitigation steps:
Affected products:
leonvanzyl autocoder
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30352
http://autocoder.com
http://leonvanzyl.com
https://gist.github.com/syphonetic/e3bdee6c022b36d5ecb98fbf61284931
https://github.com/leonvanzyl/autocoder
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
