← Back to search

CVE-2026-93349

8.8 HIGHpublic exploit available

Published 2026-09-23 · Updated 2026-09-28

AI risk analysis

Summary
This vulnerability allows an attacker to inject OS commands, leading to arbitrary command execution as the user running the explore command. It matters because it can be exploited to gain full control over the system.
Exploitability
Exploitation requires an attacker to supply a crafted Data Package descriptor, which is moderately hard due to the need for crafting the payload and placing it in the correct location.
Blast radius
If exploited, this could result in complete compromise of the system and data, as the commands are executed in the context of the user running the explore command.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Frictionless 5.19.1 or later.
rceos-command-injectiondata-package

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.