CPE
navi version 2.24.0 and earlier contains a command injection vulnerability due to improper escaping of cheatsheet variable values, allowing arbitrary command execution via crafted file names.