CERT Polska disclosed four vulnerabilities in the nnn file manager, confirming that version 5.2 is affected. The issues include CVE-2026-65609, an out-of-bounds write triggered by a crafted session file; CVE-2026-65610, a numeric truncation error classified as CWE-197 involving the HOME path that can cause out-of-bounds read and write; and CVE-2026-65611 plus CVE-2026-65612, two OS command injection flaws caused by unsanitized directory and filename values.
Successful exploitation could let an attacker corrupt memory or execute attacker-controlled shell commands with the privileges of the nnn process. CERT Polska said it coordinated disclosure with the project maintainer, but a complete vulnerable version range was not provided, leaving only version 5.2 confirmed as vulnerable at publication.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 19 August 2026, CERT Polska disclosed four vulnerabilities in the nnn file manager: CVE-2026-65609, CVE-2026-65610, CVE-2026-65611, and CVE-2026-65612. CERT Polska confirmed version 5.2 as vulnerable and noted the maintainer did not provide a full vulnerable version range.
CERT Polska said Michał Majchrowicz and Marcin Wyczechowski of the AFINE Team were credited for the responsible vulnerability report, and that disclosure was coordinated with the nnn project maintainer. The report covered four flaws in nnn, including memory corruption and command injection issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcecert.pl
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.