VYPR

CVE-2026-93349-frictionless-command-injection

by SaiTeja Erukude

CVEs (1)

  • CVE-2026-93349HigSep 23, 2026
    risk 0.50cvss 8.8epss

    Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place…