Description
JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Operating-system Command Injection
Action: Immediate Patch
AI Analysis

Impact

JabRef provides a built‑in HTTP server that exposes a /better‑bibtex/cayw endpoint. The endpoint accepts a query parameter that specifies an external command. On Unix‑like systems the value is concatenated with citation keys and passed directly to sh -c through ProcessBuilder, without any escaping. This allows an attacker who can send a request to localhost to inject shell metacharacters and execute arbitrary operating‑system commands with the privileges of the JabRef process.

Affected Systems

Versions of JabRef prior to 6.0‑alpha.6 are affected. The vulnerability exists only when the built‑in server (jabsrv) is enabled or when jabsrv is run. By default the server is disabled, so an attacker must enable it or install jabsrv. The flaw operates on Unix‑like operating systems.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while an EPSS score of <1% and absence from CISA’s KEV catalog imply a low probability that it will be actively exploited. The attack vector requires local access to the victim’s machine and the ability to issue an HTTP request to the enabled server. If successful, the attacker can run arbitrary shell commands as the JabRef user, potentially compromising system integrity and confidentiality. Though unlikely in practice due to the local‑only nature of the server, the impact of a successful exploit is significant.

Generated by OpenCVE AI on September 19, 2026 at 02:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JabRef to version 6.0‑alpha.6 or later to remove the vulnerable command handling.
  • If upgrading is not feasible, disable the built‑in HTTP server (jabsrv) so that the /better‑bibtex/cayw endpoint is not reachable.
  • Avoid configuring a Sublime Text command path or remove the CAYW integration entirely to eliminate the shell execution path.

Generated by OpenCVE AI on September 19, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Jabref
Jabref jabref
Vendors & Products Jabref
Jabref jabref

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.
Title JabRef CAYW Sublime Text integration permits operating-system command injection
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:23.379Z

Reserved: 2026-06-09T17:30:33.457Z

Link: CVE-2026-53534

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:15.506Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:16:59.617

Modified: 2026-09-24T21:17:43.237

Link: CVE-2026-53534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:15:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')