{"id":"CVE-2026-106057","summary":"patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt","details":"patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.","modified":"2026-10-08T02:50:33.193836725Z","published":"2026-10-07T11:59:37.019Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106057.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106057.json"},{"type":"PACKAGE","url":"https://github.com/wummel/patool"},{"type":"ARTICLE","url":"https://github.com/wummel/patool/blob/4.0.5/patoolib/util.py#L110-L116"},{"type":"FIX","url":"https://github.com/wummel/patool/commit/592f35761f428afbcde2888ecd3cc4af43881aeb"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106057"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/patool-before-4.0.6-os-command-injection-on-windows-via-shell-quote-nt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wummel/patool","events":[{"introduced":"0"},{"fixed":"b1a2f6fcaa74393ea4e70061744939ec0af8bf5c"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"4.0.6"}]}}],"versions":["4.0.5","4.0.4","4.0.3","4.0.2","4.0.1","4.0.0","3.1.3","3.1.2","3.1.1","3.1.0","3.0.3","3.0.2","3.0.1","3.0.0","2.4.0","upstream/2.4.0","dist/patool-2.4.0-py2.py3-none-any.whl","upstream/2.3.0","upstream/2.2.0","upstream/2.1.1","upstream/2.1.0","upstream/2.0.0","upstream/1.15.0","upstream/1.14.1","upstream/1.14.0","upstream/1.13","upstream/1.12","upstream/1.11","upstream/1.10","upstream/1.9","upstream/1.8","upstream/1.7","upstream/1.6","upstream/1.5","upstream/1.4","upstream/1.2","upstream/1.1","upstream/1.0","upstream/0.19","upstream/0.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106057.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}