CVE-2026-106057
Received Received - Intake

patool OS Command Injection on Windows

Vulnerability report for CVE-2026-106057, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wummel patool 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

patool before 4.0.6 has an OS command injection flaw on Windows due to improper escaping in the shell_quote_nt function. Attackers can craft filenames with cmd.exe metacharacters or quotes, like report&calc.gz, to execute arbitrary commands when patool processes single-file formats with shell=True.

Detection Guidance

Check patool version with 'patool --version'. If version is below 4.0.6, the system is vulnerable. Inspect archive filenames for cmd.exe metacharacters like &, |, <, >, ^, (, ), ", !, or embedded quotes. Monitor process execution logs for unexpected commands spawned by patool.

Impact Analysis

If exploited, attackers could run malicious commands on your system with the same privileges as the patool process. This could lead to data theft, system compromise, or further network infiltration depending on the patool process permissions.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by enabling unauthorized data access or modification if patool is used in systems handling sensitive data. Compliance may require patching to prevent breaches and ensure data integrity.

Mitigation Strategies

Update patool to version 4.0.6 or later immediately. Avoid using patool with untrusted archive files. If updating is not possible, restrict patool usage to trusted users and disable shell=True in patool operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106057. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart