CVE-2026-93349
Frictionless OS Command Injection via explore Console Command
- Published
- Sep 23, 2026
- Updated
- Sep 23, 2026
- Assigning CNA
- VulnCheck
- Evidence observed
- Sep 23, 2026
Primary CVSS
cvelist · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NSummary
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.
Sources
1Proof-of-concept for CVE-2026-93349, an OS command injection in Frictionless <= 5.20.0rc1 explore CLI via malicious Data Package descriptor paths.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.