{"id":"CVE-2026-93349","summary":"Frictionless OS Command Injection via explore Console Command","details":"Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.","modified":"2026-09-25T03:48:55.592861839Z","published":"2026-09-23T16:34:57.201Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93349.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93349.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93349"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/frictionless-os-command-injection-via-explore-console-command"},{"type":"REPORT","url":"https://github.com/frictionlessdata/frictionless-py/pull/1820"},{"type":"PACKAGE","url":"https://github.com/frictionlessdata/frictionless-py"},{"type":"EVIDENCE","url":"https://github.com/SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frictionlessdata/frictionless-py","events":[{"introduced":"0"},{"fixed":"7c3befb01f6c78e14b5320d9a2e4d943f7cd761b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.20.0rc1"},{"fixed":"5.20.0rc1"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v5.19.0","v5.18.1","v5.18.0","v5.17.0","v5.16.1","v5.16.0","v5.15.12","v5.15.11","v5.15.10","v5.15.9","v5.15.8","v5.15.7","v5.15.6","v5.15.5","v5.15.4","v5.15.3","v5.15.2","v5.15.0","v5.14.5","v5.14.4","v5.14.3","v5.14.2","v5.14.1","v5.14.0","v5.13.1","v5.13.0","v5.12.1","v5.12.0","v5.11.1","v5.11.0","v5.10.5","v5.10.4","v5.10.3","v5.10.2","v5.10.1","v5.10.0","v5.8.3","v5.8.2","v5.8.1","v5.8.0","v5.7.2","v5.7.1","v5.7.0","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v5.5.10","v5.5.9","v5.5.8","v5.5.7","v5.5.6","v5.5.5","v5.5.4","v5.5.3","v5.5.2","v5.5.1","v5.5.0","v5.4.0","v5.3.0","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.2","v5.1.1","v5.1.0","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v5.0.0b23","v5.0.0b22","v5.0.0b21","v5.0.0b20","v5.0.0b19","v5.0.0b18","v5.0.0b17","v5.0.0b16","v5.0.0b15","v5.0.0b14","v5.0.0b13","v5.0.0b12","v5.0.0b11","v5.0.0b10","v5.0.0b9","v5.0.0b7","v5.0.0b6","v5.0.0b5","v5.0.0b4","v5.0.0b3","v5.0.0b2","v5.0.0b1","v4.40.7","v4.40.6","v4.40.5","v4.40.4","v4.40.3","v4.40.2","v4.40.1","v4.40.0","v4.39.0","v4.38.0","v4.37.0","v4.36.0","v4.35.0","v4.34.0","v4.33.0","v4.32.1","v4.32.0","v4.31.0","v4.29.0","v4.28.3","v4.28.2","v4.28.1","v4.28.0","v4.27.0","v4.26.2","v4.26.1","v4.26.0","v4.25.1","v4.25.0","v4.24.0","v4.23.2","v4.23.1","v4.23.0","v4.22.3","v4.22.2","v4.22.1","v4.22.0","v4.21.2","v4.21.1","v4.21.0","v4.20.2","v4.20.1","v4.20.0","v4.19.6","v4.19.5","v4.19.4","v4.19.3","v4.19.2","v4.19.1","v4.19.0","v4.18.2","v4.18.1","v4.18.0","v4.17.5","v4.17.4","v4.17.3","v4.17.2","v4.17.1","v4.17.0","v4.16.8","v4.16.7","v4.16.6","v4.16.5","v4.16.4","v4.16.3","v4.16.2","v4.16.1","v4.16.0","v4.15.0","v4.14.2","v4.14.1","v4.14.0","v4.13.0","v4.12.9","v4.12.8","v4.12.7","v4.12.6","v4.12.5","v4.12.4","v4.12.3","v4.12.2","v4.12.1","v4.12.0","v4.11.0","v4.10.7","v4.10.6","v4.10.5","v4.10.4","v4.10.3","v4.10.2","v4.10.1","v4.10.0","v4.9.5","v4.9.4","v4.9.3","v4.9.2","v4.9.1","v4.9.0","v4.8.1","v4.8.0","v4.7.5","v4.7.4","v4.7.3","v4.7.2","v4.7.1","v4.7.0","v4.6.1","v4.6.0","v4.5.2","v4.5.1","v4.5.0","v4.4.2","v4.4.1","v4.4.0","v4.3.2","v4.3.1","v4.3.0","v4.2.2","v4.2.1","v4.2.0","v4.1.0","v4.0.13","v4.0.12","v4.0.11","v4.0.10","v4.0.9","v4.0.8","v4.0.7","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v4.0.0a17","v4.0.0a16","v4.0.0a15","v4.0.0a14","v4.0.0a13","v4.0.0a12","v4.0.0a11","v4.0.0a10","v4.0.0a9","v4.0.0a8","v4.0.0a7","v4.0.0a6","v4.0.0a5","v4.0.0a4","v4.0.0a3","v4.0.0a2","v4.0.0a1","v3.48.0","v3.47.3","v3.47.2","v3.47.1","v3.47.0","v3.46.0","v3.45.5","v3.45.4","v3.45.3","v3.45.2","v3.45.1","v3.45.0","v3.44.0","v3.43.0","v3.42.0","v3.41.0","v3.40.0","v3.39.0","v3.38.2","v3.38.1","v3.38.0","v3.37.0","v3.36.0","v3.35.0","v3.34.4","v3.34.3","v3.34.2","v3.34.1","v3.34.0","v3.33.3","v3.33.2","v3.33.1","v3.33.0","v3.32.0","v3.31.0","v3.30.0","v3.29.0","v3.28.0","v3.27.3","v3.27.2","v3.27.1","v3.27.0","v3.26.0","v3.25.2","v3.25.1","v3.25.0","v3.24.1","v3.24.0","v3.23.6","v3.23.5","v3.23.4","v3.23.3","v3.23.2","v3.23.1","v3.23.0","v3.22.1","v3.22.0","v3.21.0","v3.20.0","v3.19.2","v3.19.1","v3.19.0","v3.18.1","v3.18.0","v3.17.0","v3.16.0","v3.15.0","v3.14.0","v3.13.0","v3.12.0","v3.11.1","v3.11.0","v3.10.0","v3.9.1","v3.9.0","v2.5.0","v2.4.16","v2.4.15","v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5","v2.4.4","v2.4.3","v2.4.2","v2.4.1","v2.4.0","v2.3.1","v2.3.0","v2.2.1","v2.2.0","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.2","v2.0.0","v1.5.1","v1.5.0","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v1.0.0-alpha16","v1.0.0-alpha15","v1.0.0-alpha13","v1.0.0-alpha12","v1.0.0-alpha11","v1.0.0-alpha10","v1.0.0-alpha9","v1.0.0-alpha8","v1.0.0-alpha7","v1.0.0-alpha6","v1.0.0-alpha5","v1.0.0-alpha4","v1.0.0-alpha3","v1.0.0-alpha2","v1.0.0-alpha1","0.6.0","0.5.7","v0.5.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93349.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}