NPM · AUGUST 2026 · EARLY WARNING

ICEcoder 8.1 Remote Code Execution Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
icecoder (npm)
Affected versions
>= 8.0, <= 8.0 or >= 8.0beta, <= 8.0beta or >= 7.0beta, <= 7.0beta or >= 7.0, <= 7.0 or >= v6.0, <= v6.0 or >= v6.0beta, <= v6.0beta or >= v5.7, <= v5.7 or >= v5.6, <= v5.6 or >= v5.5, <= v5.5 or >= v5.4, <= v5.4 or >= v5.3, <= v5.3 or >= v5.2, <= v5.2 or >= v5.1, <= v5.1 or >= v5.0, <= v5.0 or >= v5.0beta, <= v5.0beta or >= v4.5, <= v4.5 or >= v4.4, <= v4.4 or >= v4.3, <= v4.3 or >= v4.2, <= v4.2 or >= v4.1, <= v4.1 or >= v4.0, <= v4.0 or >= v4.0beta, <= v4.0beta or >= v3.5, <= v3.5 or >= v3.4, <= v3.4 or >= v3.3, <= v3.3 or >= v3.2, <= v3.2 or >= v3.1, <= v3.1 or >= v3.0, <= v3.0 or >= v3.0beta, <= v3.0beta or >= v2.5, <= v2.5 or >= v2.4, <= v2.4 or >= v2.3, <= v2.3 or >= v2.2, <= v2.2 or >= v2.1, <= v2.1 or >= v2.0, <= v2.0 or >= v2.0beta, <= v2.0beta or >= v1.6, <= v1.6 or >= v1.5, <= v1.5 or >= v1.4, <= v1.4 or >= v1.3, <= v1.3 or >= v1.2, <= v1.2 or >= v1.1, <= v1.1 or >= v1.0.0, <= v1.0.0 or >= v0.9.1, <= v0.9.1 or >= v0.9.0, <= v0.9.0 or >= v0.8.6, <= v0.8.6 or >= v0.8.5, <= v0.8.5 or >= v0.8.4, <= v0.8.4 or >= v0.8.3, <= v0.8.3 or >= v0.8.2, <= v0.8.2 or >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.9, <= v0.7.9 or >= v0.7.8, <= v0.7.8 or >= v0.7.7, <= v0.7.7 or >= v0.7.6, <= v0.7.6 or >= v0.7.5, <= v0.7.5 or >= v0.7.4, <= v0.7.4 or >= v0.7.3, <= v0.7.3 or >= v0.7.2, <= v0.7.2 or >= v0.7.1, <= v0.7.1 or >= v0.7.0, <= v0.7.0 or >= v0.6.9, <= v0.6.9 or >= v0.6.8, <= v0.6.8 or >= v0.6.7, <= v0.6.7 or >= v0.6.6, <= v0.6.6 or >= v0.6.5, <= v0.6.5 or >= v0.6.4, <= v0.6.4 or >= v0.6.3, <= v0.6.3 or >= v0.6.2, <= v0.6.2 or >= v0.6.1, <= v0.6.1 or >= v0.6.0, <= v0.6.0 or >= v0.5.9, <= v0.5.9
Patched version
Not yet available
CVE-2026-63722

ICEcoder 8.1 is under investigation for an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary OS commands. Users of affected versions should assess their exposure immediately.

What happened

ICEcoder 8.1 reportedly contains a vulnerability that permits unauthenticated remote code execution. Attackers can exploit this by sending a specially crafted HTTP POST request to the terminal endpoint. This allows them to bypass authentication and CSRF validation, and execute arbitrary commands as the web-server user.

The vulnerability affects all versions of ICEcoder from 0.5.9 and above. The specific versions impacted range from v0.5.9 to v8.1 inclusive. There is currently no official fix published, and users are advised to monitor updates from the primary sources.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If icecoder is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using any version of ICEcoder from v0.5.9 to v8.1 inclusive.

What should I do right now?

Monitor the primary sources for updates on a patched version. If a patch becomes available, upgrade immediately. In the absence of a patch, consider removing or isolating the affected ICEcoder instances.

Is there a patched version available?

No official fix has been published yet. Continue to monitor the primary sources for updates.

How can I limit the impact of this vulnerability?

Review your network and server configurations to limit the potential impact of remote code execution.

Sources

Join the 0Day waitlist →

← Back to all threats