OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-93349

HIGH · CVSS 8.8 EPSS 2.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit the explore console command in Frictionless versions up to 5.20.0rc1 by injecting arbitrary OS commands through crafted Data Package descriptors. This can lead to unauthorized command execution in the context of the user running the explore command, potentially compromising system integrity. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-93349
Severity
HIGH
CVSS
8.8
EPSS
2.12%

Original NVD Description

Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.