๐Ÿ” CVE Alert

CVE-2026-53534

UNKNOWN 0.0

JabRef CAYW Sublime Text integration permits operating-system command injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.

CWE CWE-78
Vendor jabref
Product jabref
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for jabref jabref

Be the first to know when new unknown vulnerabilities affecting jabref jabref are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

JabRef / jabref
< 6.0-alpha.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/JabRef/jabref/security/advisories/GHSA-m42c-cw93-p629 github.com: https://github.com/JabRef/jabref/pull/15628 github.com: https://github.com/JabRef/jabref/commit/b8663fe58e6c87c3927cdb4eeb1f6934d7c3f1d2 github.com: https://github.com/JabRef/jabref/releases/tag/v6.0-alpha.6