Impact
pbi-cli 3.10.1 through 3.12.0 includes operating‑system command injection flaw located in desktop_sync.py. The flaw corresponds to CWE‑78, OS Command Injection. The vulnerability arises when the program passes unquoted .pbip project paths directly to the Windows shell via cmd /c start. Attackers can craft paths that include special characters such as ampersands, allowing execution of arbitrary shell commands with the privileges of the user opening the file. By luring a victim into opening a project stored in a path designed to trigger the injection, the attacker can execute code at the time the report is written or reloaded.
Affected Systems
The issue affects the MinaSaad1 pbi-cli product, specifically versions 3.10.1 through 3.12.0. No other vendors or versions are listed as impacted. The software is a command‑line interface for interacting with Power BI projects, and the vulnerable code path is active when the desktop sync feature is used to reopen projects from shared locations.
Risk and Exploitability
The flaw has a CVSS score of 7.3, indicating high severity. EPSS information is not available, and the vulnerability is not presently listed in the CISA KEV catalog. The likely attack vector involves an adversary providing a specially crafted i/o path containing no spaces and an ampersand to a user that triggers the vulnerable code when opening a project. Because the affected code executes with the user’s privileges, successful exploitation would allow the attacker to run arbitrary commands on the victim’s system. The risk is therefore significant for organizations that enable desktop sync and allow untrusted paths to be opened by users.
OpenCVE Enrichment