{"cve":"CVE-2026-93349","enrichment":{"created":"2026-09-23T17:30:06.829502+00:00","updated":"2026-09-23T17:30:06.829515+00:00","vendors":[]},"mitre":{"cpes":[],"created":"2026-09-23T16:34:57.201000+00:00","description":"Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":8.6,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/93xxx/CVE-2026-93349.json","references":["https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection","https://github.com/frictionlessdata/frictionless-py/pull/1820","https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command"],"title":"Frictionless OS Command Injection via explore Console Command","updated":"2026-09-23T18:40:13.306000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2026-09-23T17:17:19.653000+00:00","description":"Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":8.6,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-93349.json","references":["https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection","https://github.com/frictionlessdata/frictionless-py/pull/1820","https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command"],"title":null,"updated":"2026-09-23T19:19:44.883000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2026-09-23T16:45:00+00:00","data":[{"details":{"new":"Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.","old":null},"type":"description"},{"details":{"new":"Frictionless OS Command Injection via explore Console Command","old":null},"type":"title"},{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection","https://github.com/frictionlessdata/frictionless-py/pull/1820","https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":8.6,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"c5832bae-bcf0-4773-a0dc-1a8b479f9b5f"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-23T16:34:57.201000+00:00","provider":"mitre"},"description":{"data":"Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{"score":8.6,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection","https://github.com/frictionlessdata/frictionless-py/pull/1820","https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command"],"providers":["mitre","nvd"]},"title":{"data":"Frictionless OS Command Injection via explore Console Command","provider":"mitre"},"updated":{"data":"2026-09-23T16:34:57.201000+00:00","provider":"mitre"},"vendors":{"data":[],"providers":[]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}}}