Description
patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.
Published: 2026-10-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: OS Command Injection that allows arbitrary command execution on Windows.
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from patool's shell_quote_nt function failing to escape cmd.exe metacharacters or embedded double quotes in archive filenames. This flaw allows attackers to supply crafted filenames such as report&calc.gz and cause patool to run them as shell commands under the patool process via shell=True. If exploited, an attacker can execute arbitrary commands with the privileges of the user running patool, leading to full system compromise.

Affected Systems

Patool, released by wummel, is vulnerable on all versions earlier than 4.0.6 when executed on Windows. Any Windows system that uses an older patool package to extract archives that contain specially crafted filenames is at risk. The problem resides exclusively in the Windows environment and does not affect other operating systems.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. Because the EPSS score is not available, the exact likelihood of exploitation remains unknown, but the vulnerability is listed in no KEV catalogue, implying no known widespread exploitation. The attack vector is local as an attacker must supply a malicious archive; however, if an attacker can write to a shared location or upload a file to a service that invokes patool, the risk grows. Exploitation requires use of shell=True by patool, which is the default for many formats, making mitigations straightforward by upgrading.

Generated by OpenCVE AI on October 7, 2026 at 13:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade patool to version 4.0.6 or later to receive the fixed shell_quote_nt implementation.
  • For scripts that call patool directly, avoid using the shell=True parameter or modify the code to use safe extraction methods that do not rely on the vulnerable function.
  • Validate and sanitize archive filenames before extraction, removing or escaping metacharacters, or use a tool to scan archives for suspicious filenames as a temporary workaround.

Generated by OpenCVE AI on October 7, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wummel
Wummel patool
Vendors & Products Wummel
Wummel patool

Wed, 07 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Description patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges.
Title patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T11:59:37.019Z

Reserved: 2026-10-06T14:14:17.255Z

Link: CVE-2026-106057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T12:17:08.730

Modified: 2026-10-07T12:17:08.730

Link: CVE-2026-106057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T13:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')