CVE-2026-28207Patch(zenc-lang / zen_c)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zenc-lang zen_c systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` command-line argument. The vulnerability existed in the `main` application logic (specifically in `src/main.c`), where the compiler constructed a shell command string to invoke the backend C compiler. This command string was built by concatenating various arguments, including the user-controlled output filename, and was subsequently executed using the `system()` function. Because `system()` invokes a shell to parse and execute the command, shell metacharacters within the output filename were interpreted by the shell, leading to arbitrary command execution. An attacker who can influence the command-line arguments passed to the `zc` compiler (like through a build script or a CI/CD pipeline configuration) can execute arbitrary commands with the privileges of the user running the compiler. The vulnerability has been fixed in version 0.4.2 by removing `system()` calls, implementing `ArgList`, and internal argument handling. Users are advised to update to Zen C version v0.4.2 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zen_c

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
zen_c

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-27: 102-2602-27
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-261
Patch1
2026-02-271
Disclosure1
Full discourse2 posts
  • Zuhaitz@zuhaitz_dev
    Patch

    Zen-C v0.4.2 is live now! This is another major update featuring several new features, such as first-class SIMD, plus a critical security fix for CVE-2026-28207. Release: https://github.com/z-libs/Zen-C/releases/tag/v0.4.2 Security Advisory: https://github.com/z-libs/Zen-C/security/advisories/GHSA-9rff-x96h-76h2 > As if it was not clear enough, move to the newer version.

    Post summary

    Zen‑C v0.4.2 includes a critical fix for CVE‑2026‑28207 and recommends users upgrade to the new release.

    2212543.7K
    6.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28207 Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C com… https://www.cve.org/CVERecord?id=CVE-2026-28207

    Post summary

    A command injection vulnerability (CWE-78) has been disclosed for Zen C versions prior to 0.4.2, identified as CVE-2026-28207.

    00000256
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzenc-langzen_c---

Explore more