Once Francesco reported a similar issue to us for Breakdance, we invited them to investigate Oxygen as well. On May 7th, they alerted us to this vulnerability in Oxygen and we immediately began work to remediate the issue.
This reiterates the importance of regular, high quality security audits, a long-time standard practice here at Soflyy. Please note that any reports about this issue coming out through Patchstack are from other security researchers attempting to replicate the Breakdance RCE in Oxygen, and that the discovery should be credited to Francesco Carlucci who validated CVE-2024-4662 on May 8th via WordFence.