Retour à la veille

CVE-2026-101032

Publié : 27 septembre 2026
Modifié : 27 septembre 2026
Lien officiel NVD
Score CVSS
7
HIGH

Description détaillée

navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Références et Patchs