initiateGqlAPIProcess of the component GraphQL. Such manipulation leads to os command injection.This vulnerability is documented as CVE-2026-40520. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
SOCIAL SHARE CARD GENERATOR