CVE-2026-93349
8.8 HIGHpublic exploit availablePublished 2026-09-23 · Updated 2026-09-28
AI risk analysis
- Summary
- This vulnerability allows an attacker to inject OS commands, leading to arbitrary command execution as the user running the explore command. It matters because it can be exploited to gain full control over the system.
- Exploitability
- Exploitation requires an attacker to supply a crafted Data Package descriptor, which is moderately hard due to the need for crafting the payload and placing it in the correct location.
- Blast radius
- If exploited, this could result in complete compromise of the system and data, as the commands are executed in the context of the user running the explore command.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Frictionless 5.19.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
All references
- https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection
- https://github.com/frictionlessdata/frictionless-py/pull/1820
- https://github.com/frictionlessdata/frictionless-py/releases/tag/v5.19.1
- https://github.com/frictionlessdata/frictionless-py/releases/tag/v5.20.0rc2
- https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-100896PoC
- CRITICALCVE-2026-101001PoC
- CRITICALCVE-2026-101002PoC
- CRITICALCVE-2026-101072PoC
- CRITICALCVE-2026-101075PoC
- CRITICALCVE-2026-101076PoC
- CRITICALCVE-2026-102911PoC
- HIGHCVE-2026-15027
Related by shared AI tags and CWE weakness class. Browse the full archive.