CVE-2026-93349 is an OS command injection vulnerability in the Frictionless explore console command. The command passes attacker-controlled resource-path values from a crafted Data Package descriptor to os.system through a shell without sanitization. Shell metacharacters embedded in those values can cause arbitrary operating-system commands to run in the security context of a user who explores the malicious package.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
explore command. This can enable an attacker to perform actions accessible to that user on the affected host.If you can’t patch tonight, do this now.
explore command on untrusted Data Packages. Treat descriptor resource-path values as untrusted input, sanitize or validate them before processing, and restrict use of the command in environments that process untrusted packages.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This nine-file Python PoC repository demonstrates CVE-2026-93349, an OS command injection in Frictionless's `explore` CLI path. `package_builder.py` creates a syntactically valid Data Package descriptor and benign CSV, but sets `resources[0].path` to a platform-specific shell-injection string. `run_poc.py` validates the descriptor, confirms that the malicious value persists through Frictionless `Resource.list()` and `resource.normpath`, then invokes the installed CLI as `python -m frictionless explore malicious-package/datapackage.json`. The reported vulnerable implementation joins resource paths into `os.system("vd ...")`, causing shell metacharacters in descriptor metadata to be interpreted. The runner empties PATH to prevent interactive VisiData execution, then verifies injection by checking for the local marker file. There are no attacker network callbacks, remote hosts, credential collection routines, or destructive actions. README, walkthrough, and fix documentation explain the vulnerable flow and recommend replacing `os.system` with `subprocess.run(["vd", *paths], shell=False)` semantics.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OS command injection vulnerability in Frictionless's explore console command. Crafted resource-path values in a datapackage.json descriptor can include shell metacharacters that are passed unsanitized to os.system, enabling arbitrary command execution under the privileges of a user who explores an untrusted package.
An OS command injection vulnerability in Frictionless through version 5.20.0rc1. Crafted resource-path values in a datapackage.json Data Package descriptor are passed unsanitized to os.system via a shell when a victim runs the explore command, enabling arbitrary command execution in that user's security context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.