{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/patool--4.0.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-106057"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["patool (\u003c 4.0.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe patool library, a portable archive file manager, is vulnerable to OS command injection in versions prior to 4.0.6 when running on Windows. The issue stems from the shell_quote_nt function, which fails to correctly sanitize or escape cmd.exe metacharacters and embedded double quotes in archive filenames. When the library processes a crafted filename containing these characters (e.g., 'report\u0026amp;calc.gz') within a context where shell=True is invoked, it inadvertently triggers the execution of arbitrary commands. This vulnerability affects any Windows-based application or service that utilizes patool to handle untrusted user-supplied archive files, potentially leading to unauthorized code execution with the permissions of the application process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the host machine with the privileges of the user running the patool-based application. This vulnerability poses a significant risk in environments where users can upload or provide archive files for automated processing, such as web applications or file-transfer services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade the patool library to version 4.0.6 or later immediately to resolve the shell_quote_nt escaping issue.\u003c/p\u003e\n\u003ch2 id=\"rules\"\u003eRules\u003c/h2\u003e\n\u003cp\u003etitle: \u0026quot;Detect Suspicious Command Execution via patool\u0026quot;\ndescription: \u0026quot;Detects potential command injection exploitation where cmd.exe metacharacters are passed to a sub-process spawned by a python application process likely using patool.\u0026quot;\nlogsource:\ncategory: process_creation\nproduct: windows\ndetection:\nselection:\nCommandLine|contains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u0026quot;\u0026amp;\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;|\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;\u0026amp;\u0026amp;\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;||\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;^\u0026quot;\nfilter:\nImage|endswith:\u003c/li\u003e\n\u003cli\u003e\u0026quot;C:\\Windows\\System32\\cmd.exe\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;C:\\Windows\\SysWOW64\\cmd.exe\u0026quot;\ncondition: selection and filter\nlevel: high\ntags:\u003c/li\u003e\n\u003cli\u003eattack.execution\u003c/li\u003e\n\u003cli\u003eattack.t1059.003\nfalsepositives:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Legitimate administrative scripts using command chaining\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;System maintenance tasks\u0026quot;\ntests:\npositive:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Cmd.exe execution with shell metacharacters in command line\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003eImage: \u0026quot;C:\\Windows\\System32\\cmd.exe\u0026quot;\nCommandLine: \u0026quot;cmd.exe /c extract file\u0026amp;calc.exe\u0026quot;\nnegative:\u003c/li\u003e\n\u003cli\u003ename: \u0026quot;Standard process creation\u0026quot;\ndata:\u003c/li\u003e\n\u003cli\u003eImage: \u0026quot;C:\\Windows\\System32\\cmd.exe\u0026quot;\nCommandLine: \u0026quot;cmd.exe /c echo hello\u0026quot;\nhandoff:\ndetection_confidence: \u0026quot;medium\u0026quot;\nrequired_telemetry:\u003c/li\u003e\n\u003cli\u003elog_source: \u0026quot;Sysmon process_creation\u0026quot;\nevent_or_channel: \u0026quot;Event ID 1\u0026quot;\nrequired_fields:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Image\u0026quot;\u003c/li\u003e\n\u003cli\u003e\u0026quot;CommandLine\u0026quot;\navailability: \u0026quot;available\u0026quot;\nnotes: \u0026quot;Monitor cmd.exe spawns for suspicious command line arguments.\u0026quot;\nvalidation:\nstatus: \u0026quot;needs_environment_validation\u0026quot;\nknown_evasions:\u003c/li\u003e\n\u003cli\u003e\u0026quot;Using alternative shells or direct API calls not involving cmd.exe.\u0026quot;\nlimitations:\u003c/li\u003e\n\u003cli\u003e\u0026quot;High potential for noise in administrative environments.\u0026quot;\ntuning:\u003c/li\u003e\n\u003cli\u003esource: \u0026quot;Administrator scripts\u0026quot;\nguidance: \u0026quot;Exclude known administrative service accounts or deployment script paths.\u0026quot;\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T12:37:23Z","date_published":"2026-10-07T12:37:23Z","id":"https://feed.craftedsignal.io/briefs/2026-10-patool-command-injection/","summary":"The patool library prior to version 4.0.6 contains an OS command injection vulnerability on Windows that allows arbitrary command execution via crafted archive filenames.","title":"OS Command Injection in patool via Malicious Filenames","url":"https://feed.craftedsignal.io/briefs/2026-10-patool-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Patool (\u003c 4.0.6)","version":"https://jsonfeed.org/version/1.1"}