CVE-2026-39087: ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
(updated )
An issue in Ntfy ntfy.sh before v.2.22.0 allows a remote attacker to execute arbitrary code via the parseActions function.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-39087 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →