{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/frictionless--5.20.0rc1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:frictionless:frictionless:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-93349"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Frictionless (\u003c= 5.20.0rc1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Frictionless"],"content_html":"\u003cp\u003eFrictionless Framework, a data processing and validation library, is susceptible to an OS command injection vulnerability identified as CVE-2026-93349. This flaw exists within the \u0026quot;explore\u0026quot; console command, which is used to inspect Data Packages. An attacker can craft a malicious \u003ccode\u003edatapackage.json\u003c/code\u003e descriptor file containing shell metacharacters within the resource path values.\u003c/p\u003e\n\u003cp\u003eWhen a user executes the \u003ccode\u003efrictionless explore\u003c/code\u003e command against this untrusted descriptor, the application passes the unsanitized path values to the \u003ccode\u003eos.system\u003c/code\u003e function. This results in the execution of arbitrary commands with the privileges of the user who initiated the explore process. This vulnerability affects all versions of Frictionless up to and including 5.20.0rc1 and represents a significant risk to data scientists and developers who may pull and inspect untrusted data packages from external repositories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the user running the Frictionless CLI. This could lead to full system compromise, data exfiltration, or the installation of persistent malicious software on the host machine. The vulnerability impacts any environment where users utilize the Frictionless framework to analyze or validate externally sourced Data Packages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of Frictionless released after 5.20.0rc1 that addresses CVE-2026-93349.\u003c/li\u003e\n\u003cli\u003eAvoid using the \u003ccode\u003efrictionless explore\u003c/code\u003e command on untrusted or unknown \u003ccode\u003edatapackage.json\u003c/code\u003e files until the software is patched.\u003c/li\u003e\n\u003cli\u003eAudit environments where the Frictionless CLI is utilized to determine exposure and ensure users are aware of the risks associated with processing untrusted package descriptors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T18:44:24Z","date_published":"2026-09-23T18:44:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-frictionless-rce/","summary":"Frictionless Framework versions up to 5.20.0rc1 contain an OS command injection vulnerability in the explore console, allowing arbitrary command execution via crafted datapackage.json files.","title":"OS Command Injection in Frictionless Data Package Explorer","url":"https://feed.craftedsignal.io/briefs/2026-09-frictionless-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Frictionless (\u003c= 5.20.0rc1)","version":"https://jsonfeed.org/version/1.1"}