CVE WATCH / VULNERABILITY DETAIL
CVE-2026-106057
HIGHCVSS 7.8NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execut
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107204 CRITICAL 9.8
- CVE-2026-106559 MEDIUM 6.3
- CVE-2026-106560 HIGH 7.1
- CVE-2026-106561 MEDIUM 5
- CVE-2026-106563 MEDIUM 5.3
- CVE-2026-106558 HIGH 8.8
- CVE-2026-106510 HIGH 7.7
- CVE-2026-106556 HIGH 7.7
- CVE-2025-70521 CRITICAL 9.8
- CVE-2025-70518 CRITICAL 10