Loading market data...
← Back to CVE feed

CVE-2026-101032

HIGH CVSS 7.0 View on NVD ↗

Description

navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Sep 27, 2026 14:16 UTC Modified: Sep 27, 2026 14:16 UTC