VYPR
High severity7.0NVD Advisory· Published Oct 11, 2026

CVE-2026-108744

CVE-2026-108744

Description

pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.

Affected products

2
  • Minasaad1/Pbi CLIreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 3.10.1 - 3.12.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.