PT-2026-95135 · Jabref · Jabref

·

CVE-2026-53534

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions JabRef versions prior to 6.0-alpha.6
Description JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. When the built-in HTTP server or jabsrv is enabled, the 'GET /better-bibtex/cayw' endpoint accepts an external command query parameter. The CAYWQueryParams.getCommand() function passes this parameter through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed via sh -c by ProcessBuilder without shell escaping. An attacker capable of triggering a localhost request with application=sublime can inject shell metacharacters to execute operating-system commands as the JabRef user, provided a valid Sublime Text command path is configured and the user completes the CAYW selection dialog.
Recommendations Update to version 6.0-alpha.6. Disable the built-in HTTP server or stop running jabsrv to prevent exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53534
GHSA-M42C-CW93-P629

Affected Products

Jabref