{"id":"CVE-2026-35581","summary":"Emissary has a Command Injection via PLACE_NAME Configuration in Executrix","details":"Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configuration-derived values — including the PLACE_NAME parameter — with insufficient sanitization. Only spaces were replaced with underscores, allowing shell metacharacters (;, |, $, `, (, ), etc.) to pass through into /bin/sh -c command execution. This vulnerability is fixed in 8.39.0.","aliases":["GHSA-6c37-7w4p-jg9v"],"modified":"2026-07-15T01:49:11.810969699Z","published":"2026-04-07T15:56:55.838Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35581.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35581.json"},{"type":"ADVISORY","url":"https://github.com/NationalSecurityAgency/emissary/security/advisories/GHSA-6c37-7w4p-jg9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35581"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nationalsecurityagency/emissary","events":[{"introduced":"0"},{"fixed":"5e3d58513b4cc0362537c60f21983d62ddf40599"}],"database_specific":{"cpe":"cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.39.0"},{"last_affected":"8.38.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["7.19.0","emissary-7.19.0","7.18.0","7.17.0","7.16.0","7.15.0","7.14.0","7.13.0","7.12.0","7.11.0","7.10.0","7.9.0","7.8.0","7.7.0","7.6.0","7.5.0","7.4.0","7.3.0","7.2.0","7.1.0","7.0.0","6.6.0","6.5.0","6.4.0","6.3.0","6.2.0","6.1.0","6.0.0","5.11.0","5.10.0","5.9.0","5.8.0","5.7.0","5.6.0","5.5.0","5.4.1","5.3.0","5.2.0","5.1.0","5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35581.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}