{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53534","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-06-09T17:30:33.457Z","datePublished":"2026-09-17T21:42:47.446Z","dateUpdated":"2026-09-24T20:55:23.379Z"},"containers":{"cna":{"title":"JabRef CAYW Sublime Text integration permits operating-system command injection","problemTypes":[{"descriptions":[{"cweId":"CWE-78","lang":"en","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","type":"CWE"}]}],"metrics":[{"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0"}}],"references":[{"name":"https://github.com/JabRef/jabref/security/advisories/GHSA-m42c-cw93-p629","tags":["x_refsource_CONFIRM"],"url":"https://github.com/JabRef/jabref/security/advisories/GHSA-m42c-cw93-p629"},{"name":"https://github.com/JabRef/jabref/pull/15628","tags":["x_refsource_MISC"],"url":"https://github.com/JabRef/jabref/pull/15628"},{"name":"https://github.com/JabRef/jabref/commit/b8663fe58e6c87c3927cdb4eeb1f6934d7c3f1d2","tags":["x_refsource_MISC"],"url":"https://github.com/JabRef/jabref/commit/b8663fe58e6c87c3927cdb4eeb1f6934d7c3f1d2"},{"name":"https://github.com/JabRef/jabref/releases/tag/v6.0-alpha.6","tags":["x_refsource_MISC"],"url":"https://github.com/JabRef/jabref/releases/tag/v6.0-alpha.6"}],"affected":[{"vendor":"JabRef","product":"jabref","versions":[{"version":"< 6.0-alpha.6","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-17T21:42:47.446Z"},"descriptions":[{"lang":"en","value":"JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6."}],"source":{"advisory":"GHSA-m42c-cw93-p629","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-53534","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-24T20:48:34.672856Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-24T20:55:23.379Z"}}]}}