{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/navi--2.24.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:navi_project:navi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-101032"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["navi (\u003c= 2.24.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["navi"],"content_html":"\u003cp\u003enavi version 2.24.0 and earlier contains a command injection vulnerability (CVE-2026-101032) resulting from the failure to properly escape cheatsheet variable values when substituting them into shell commands. An attacker can create a malicious file name within a suggestion command directory that contains shell metacharacters. When the navi utility processes these directories and consumes the file names as variables, the injected metacharacters are interpreted by the underlying shell, leading to arbitrary command execution with the privileges of the user running navi. This vulnerability affects users of the navi command-line interactive cheatsheet tool on Linux and macOS environments. Defending against this requires updating to a patched version once available and restricting write access to directory paths monitored by navi for cheatsheet suggestions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary shell commands on the host system. Given that navi is often used by developers and system administrators to manage and execute complex commands, this could lead to full compromise of the user account, lateral movement, or unauthorized access to sensitive local files and environment variables.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs for unexpected child processes spawned by the 'navi' binary or its sub-processes.\u003c/li\u003e\n\u003cli\u003eAudit directories configured for use by navi as suggestion command sources; ensure only trusted users have write access to these locations.\u003c/li\u003e\n\u003cli\u003eUpgrade to the patched version of navi (post-2.24.0) once released by the vendor to resolve the command injection flaw in variable substitution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T15:07:44Z","date_published":"2026-09-27T15:07:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-navi-command-injection/","summary":"navi version 2.24.0 and earlier contains a command injection vulnerability due to improper escaping of cheatsheet variable values, allowing arbitrary command execution via crafted file names.","title":"Command Injection in navi via Cheatsheet Variable Substitution","url":"https://feed.craftedsignal.io/briefs/2026-09-navi-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Navi (\u003c= 2.24.0)","version":"https://jsonfeed.org/version/1.1"}