Description
pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.
Published: 2026-10-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

pbi-cli 3.10.1 through 3.12.0 includes operating‑system command injection flaw located in desktop_sync.py. The flaw corresponds to CWE‑78, OS Command Injection. The vulnerability arises when the program passes unquoted .pbip project paths directly to the Windows shell via cmd /c start. Attackers can craft paths that include special characters such as ampersands, allowing execution of arbitrary shell commands with the privileges of the user opening the file. By luring a victim into opening a project stored in a path designed to trigger the injection, the attacker can execute code at the time the report is written or reloaded.

Affected Systems

The issue affects the MinaSaad1 pbi-cli product, specifically versions 3.10.1 through 3.12.0. No other vendors or versions are listed as impacted. The software is a command‑line interface for interacting with Power BI projects, and the vulnerable code path is active when the desktop sync feature is used to reopen projects from shared locations.

Risk and Exploitability

The flaw has a CVSS score of 7.3, indicating high severity. EPSS information is not available, and the vulnerability is not presently listed in the CISA KEV catalog. The likely attack vector involves an adversary providing a specially crafted i/o path containing no spaces and an ampersand to a user that triggers the vulnerable code when opening a project. Because the affected code executes with the user’s privileges, successful exploitation would allow the attacker to run arbitrary commands on the victim’s system. The risk is therefore significant for organizations that enable desktop sync and allow untrusted paths to be opened by users.

Generated by OpenCVE AI on October 11, 2026 at 14:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pbi-cli to the latest released version where the desktop_sync.py injection is fixed. If a patch is not yet available, disable the desktop sync feature for untrusted projects until a fix is issued.
  • Ensure that any .pbip file paths used with desktop sync are validated and sanitized; disallow paths that contain spaces or shell metacharacters such as ampersands. This can be achieved by implementing an input filter that escapes or rejects unsafe characters before passing the path to the shell.
  • Monitor system logs and shell activity for evidence of unexpected command execution, and restrict user permissions so that only trusted accounts can initiate project opening via desktop sync.

Generated by OpenCVE AI on October 11, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.
Title pbi-cli 3.10.1 through 3.12.0 OS Command Injection via Desktop Sync
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:46.798Z

Reserved: 2026-10-11T01:53:19.833Z

Link: CVE-2026-108744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:18.957

Modified: 2026-10-11T13:17:18.957

Link: CVE-2026-108744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')