PT-2026-95135 · Jabref · Jabref
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
JabRef versions prior to 6.0-alpha.6
Description
JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. When the built-in HTTP server or jabsrv is enabled, the 'GET /better-bibtex/cayw' endpoint accepts an external command query parameter. The
CAYWQueryParams.getCommand() function passes this parameter through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed via sh -c by ProcessBuilder without shell escaping. An attacker capable of triggering a localhost request with application=sublime can inject shell metacharacters to execute operating-system commands as the JabRef user, provided a valid Sublime Text command path is configured and the user completes the CAYW selection dialog.Recommendations
Update to version 6.0-alpha.6.
Disable the built-in HTTP server or stop running jabsrv to prevent exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jabref