A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.
https://github.com/leonvanzyl/autocoder
https://gist.github.com/syphonetic/e3bdee6c022b36d5ecb98fbf61284931