CVE-2026-106057 - patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt
CVE ID :CVE-2026-106057
Published : Oct. 7, 2026, 12:17 p.m. | 1 hour, 29 minutes ago
Description :patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 7, 2026, 12:17 p.m. | 1 hour, 29 minutes ago
Description :patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...