Impact
JabRef provides a built‑in HTTP server that exposes a /better‑bibtex/cayw endpoint. The endpoint accepts a query parameter that specifies an external command. On Unix‑like systems the value is concatenated with citation keys and passed directly to sh -c through ProcessBuilder, without any escaping. This allows an attacker who can send a request to localhost to inject shell metacharacters and execute arbitrary operating‑system commands with the privileges of the JabRef process.
Affected Systems
Versions of JabRef prior to 6.0‑alpha.6 are affected. The vulnerability exists only when the built‑in server (jabsrv) is enabled or when jabsrv is run. By default the server is disabled, so an attacker must enable it or install jabsrv. The flaw operates on Unix‑like operating systems.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of <1% and absence from CISA’s KEV catalog imply a low probability that it will be actively exploited. The attack vector requires local access to the victim’s machine and the ability to issue an HTTP request to the enabled server. If successful, the attacker can run arbitrary shell commands as the JabRef user, potentially compromising system integrity and confidentiality. Though unlikely in practice due to the local‑only nature of the server, the impact of a successful exploit is significant.
OpenCVE Enrichment