๐Ÿ” CVE Alert

CVE-2026-106057

HIGH 7.8

patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.

CWE CWE-78
Vendor wummel
Product patool
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for wummel patool

Be the first to know when new high vulnerabilities affecting wummel patool are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

wummel / patool
0 < 4.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wummel/patool/commit/592f35761f428afbcde2888ecd3cc4af43881aeb github.com: https://github.com/wummel/patool github.com: https://github.com/wummel/patool/blob/4.0.5/patoolib/util.py#L110-L116 vulncheck.com: https://www.vulncheck.com/advisories/patool-before-4.0.6-os-command-injection-on-windows-via-shell-quote-nt

Credits

Muhammad Sobirov