CVE-2026-93349
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
23/09/2026
Last modified:
23/09/2026
Description
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH


