<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Patool (&lt; 4.0.6) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/patool--4.0.6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 12:37:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/patool--4.0.6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in patool via Malicious Filenames</title><link>https://feed.craftedsignal.io/briefs/2026-10-patool-command-injection/</link><pubDate>Wed, 07 Oct 2026 12:37:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-patool-command-injection/</guid><description>The patool library prior to version 4.0.6 contains an OS command injection vulnerability on Windows that allows arbitrary command execution via crafted archive filenames.</description><content:encoded><![CDATA[<p>The patool library, a portable archive file manager, is vulnerable to OS command injection in versions prior to 4.0.6 when running on Windows. The issue stems from the shell_quote_nt function, which fails to correctly sanitize or escape cmd.exe metacharacters and embedded double quotes in archive filenames. When the library processes a crafted filename containing these characters (e.g., 'report&amp;calc.gz') within a context where shell=True is invoked, it inadvertently triggers the execution of arbitrary commands. This vulnerability affects any Windows-based application or service that utilizes patool to handle untrusted user-supplied archive files, potentially leading to unauthorized code execution with the permissions of the application process.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution on the host machine with the privileges of the user running the patool-based application. This vulnerability poses a significant risk in environments where users can upload or provide archive files for automated processing, such as web applications or file-transfer services.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Upgrade the patool library to version 4.0.6 or later immediately to resolve the shell_quote_nt escaping issue.</p>
<h2 id="rules">Rules</h2>
<p>title: &quot;Detect Suspicious Command Execution via patool&quot;
description: &quot;Detects potential command injection exploitation where cmd.exe metacharacters are passed to a sub-process spawned by a python application process likely using patool.&quot;
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:</p>
<ul>
<li>&quot;&amp;&quot;</li>
<li>&quot;|&quot;</li>
<li>&quot;&amp;&amp;&quot;</li>
<li>&quot;||&quot;</li>
<li>&quot;^&quot;
filter:
Image|endswith:</li>
<li>&quot;C:\Windows\System32\cmd.exe&quot;</li>
<li>&quot;C:\Windows\SysWOW64\cmd.exe&quot;
condition: selection and filter
level: high
tags:</li>
<li>attack.execution</li>
<li>attack.t1059.003
falsepositives:</li>
<li>&quot;Legitimate administrative scripts using command chaining&quot;</li>
<li>&quot;System maintenance tasks&quot;
tests:
positive:</li>
<li>name: &quot;Cmd.exe execution with shell metacharacters in command line&quot;
data:</li>
<li>Image: &quot;C:\Windows\System32\cmd.exe&quot;
CommandLine: &quot;cmd.exe /c extract file&amp;calc.exe&quot;
negative:</li>
<li>name: &quot;Standard process creation&quot;
data:</li>
<li>Image: &quot;C:\Windows\System32\cmd.exe&quot;
CommandLine: &quot;cmd.exe /c echo hello&quot;
handoff:
detection_confidence: &quot;medium&quot;
required_telemetry:</li>
<li>log_source: &quot;Sysmon process_creation&quot;
event_or_channel: &quot;Event ID 1&quot;
required_fields:</li>
<li>&quot;Image&quot;</li>
<li>&quot;CommandLine&quot;
availability: &quot;available&quot;
notes: &quot;Monitor cmd.exe spawns for suspicious command line arguments.&quot;
validation:
status: &quot;needs_environment_validation&quot;
known_evasions:</li>
<li>&quot;Using alternative shells or direct API calls not involving cmd.exe.&quot;
limitations:</li>
<li>&quot;High potential for noise in administrative environments.&quot;
tuning:</li>
<li>source: &quot;Administrator scripts&quot;
guidance: &quot;Exclude known administrative service accounts or deployment script paths.&quot;</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>