Sceawere

Vulnerability Detail

CVE-2026-101032UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

navi Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
18h ago
Vendor
denisidoro
Product
navi
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-09-27T14:16:28.190Z",
  "pubdate": "2026-09-27T14:16:28.190Z",
  "executiveSummary": "The vulnerability identified in navi through version 2.24.0 is a command injection flaw resulting from improper input sanitization of cheatsheet variables.\nThis vulnerability allows an attacker to execute arbitrary shell commands with the privileges of the user running navi.\nThe root cause is the unsafe substitution of variable values, sourced from file names within suggestion command directories, into shell execution contexts without adequate escaping of shell metacharacters.\nThis flaw presents a significant security risk, as it enables local attackers to achieve arbitrary code execution by crafting malicious file names.\nExploitation requires an attacker to influence the contents of a directory parsed by navi as a cheatsheet source.\nThere are no authentication requirements for this exploitation, provided the attacker can introduce a crafted filename into the system environment where the tool processes cheatsheets.\nThe impact includes full compromise of the user's session, potential data exfiltration, and unauthorized lateral movement within the local environment.",
  "technicalDetails": "The vulnerability resides in the way navi processes and substitutes variable values from cheatsheets into command execution pipelines.\nThe application architecture relies on parsing local directories to populate suggestion commands, where filenames or contents are often treated as dynamic variables.\nWhen these variables are interpolated into shell commands, the application fails to perform rigorous validation or sanitization of input strings.\nSpecifically, the tool does not escape shell metacharacters (such as backticks, semicolons, pipes, or dollar-sign subshells) present in the source filenames used as variable values.\nAn attacker can exploit this by creating a file with a name containing shell injection payloads—for example, a filename containing '$(malicious_command)' or '; command ;'.\nWhen the victim utilizes the navi interface to select this specific suggestion, the application executes a shell command that includes the unsanitized malicious filename.\nThe shell interprets the injected characters as control operators, resulting in the execution of the attacker-supplied command within the context of the user process.\nBecause navi executes these commands within the user's current environment, the injected payload inherits the user's full permission set, effectively bypassing intended functional boundaries.\nThis vulnerability is present in all versions up to and including 2.24.0.\nThere are no requirements for network access as the exploit vector is local; the attacker needs only the ability to place a crafted file in a directory that is subsequently indexed or parsed by navi.\nThe impact of a successful exploit includes complete control over the victim's local process, enabling the execution of arbitrary commands, extraction of sensitive configuration data, or the establishment of persistent backdoors within the user profile."
}
CVE-2026-101032: navi Command Injection Vulnerability (HIGH Severity, CVSS: 7.0) | Sceawere