---
cve: "CVE-2026-101032"
severity: "HIGH"
cvss: 7.3
epss: "0.1%"
vendor: "denisidoro"
kev: false
exploited: false
published: "2026-09-27 14:16:28"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T05:34:40+02:00"
---

# CVE-2026-101032

> 7.3 HIGH · 🧪 PoC

## Beschreibung

navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-09-28 13:13:39
- CNA-CVSS: **7.3** (`CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |

## Patch verfügbar (OSV)

- 5515367dc8a2a561d2d82b8352f729b1da4120d3 (Commit)

## Referenzen

- <https://github.com/denisidoro/navi/issues/1037>
- <https://github.com/denisidoro/navi/blob/5515367dc8a2a561d2d82b8352f729b1da4120d3/src/commands/core/actor.rs#L159-L193>
- <https://github.com/denisidoro/navi/blob/5515367dc8a2a561d2d82b8352f729b1da4120d3/src/common/shell.rs#L39-L50>
- <https://github.com/denisidoro/navi>
- <https://www.vulncheck.com/advisories/navi-through-2.24.0-os-command-injection-via-cheatsheet-variables>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-101032) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
