Sceawere

Vulnerability Detail

CVE-2026-108744UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

pbi-cli OS Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
4h ago
Vendor
MinaSaad1
Product
pbi-cli
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-10-11T13:17:18.957Z",
  "pubdate": "2026-10-11T13:17:18.957Z",
  "executiveSummary": "pbi-cli versions 3.10.1 through 3.12.0 are susceptible to an OS command injection vulnerability located within the desktop_sync.py module.\nThe vulnerability arises from the improper handling of project file paths, specifically when passing unquoted .pbip paths to the system shell via the 'cmd /c start' command.\nAn attacker can exploit this flaw by crafting a malicious Power BI project path that incorporates shell metacharacters, specifically the ampersand (&).\nWhen a victim attempts to open, write, or reload a project from such a path, the application inadvertently executes arbitrary system commands with the privileges of the currently logged-in user.\nThis vulnerability presents a significant security risk, as successful exploitation enables local code execution without requiring prior authentication, potentially leading to full system compromise depending on the user's privilege level.\nThe exploit is triggered via local file interaction, requiring the victim to open or synchronize a project located in a directory structure manipulated by the attacker.",
  "technicalDetails": "The root cause of this vulnerability is the unsafe construction of a command string within the desktop_sync.py file of the pbi-cli utility. Specifically, the application logic attempts to trigger a project synchronization or reload process by spawning a new shell process using the Windows 'cmd /c start' command. The implementation fails to properly sanitize or encapsulate the .pbip file path provided to this command.\nBecause the path is passed as an unquoted string, the command interpreter parses characters within the file path as shell operators rather than literal components of the file path. The presence of the '&' metacharacter is particularly critical, as it acts as a command separator in the Windows shell, allowing an attacker to terminate the intended command and append arbitrary instructions.\nThe attack flow begins when an attacker places a malicious .pbip file within a directory structure containing shell-sensitive characters. When the victim initiates a project synchronization or a 'reopen' operation, the pbi-cli utility invokes 'cmd /c start <path_to_pbip>'. If the path is crafted as, for example, 'C:\\Path\\To\\File & <malicious_command>\\project.pbip', the shell executes 'start C:\\Path\\To\\File' followed immediately by the execution of the <malicious_command>.\nThis mechanism bypasses existing file-level permissions, as the payload executes within the context of the user running the pbi-cli application. The vulnerability does not require network exposure, as it relies on the local execution of the affected Python script. Furthermore, there are no complex authentication requirements for the injection itself, as the trigger is the legitimate functionality of the application acting upon a user-provided (or attacker-provided) file path.\nPost-exploitation, an attacker can achieve persistent code execution, exfiltrate local data, or pivot to further internal systems. Since the execution context is the victim's user session, the severity is contingent on the privileges assigned to that user account. The failure to use parameterized process calls or proper path escaping represents a fundamental flaw in the handling of system-level interfaces within the tool."
}
CVE-2026-108744: pbi-cli OS Command Injection (HIGH Severity, CVSS: 7.0) | Sceawere