OS Command Injection Vulnerability in navi by denisidoro
CVE-2026-101032
7.3HIGH
What is CVE-2026-101032?
The navi application, up to version 2.24.0, presents a vulnerability that allows inadequate escaping of cheatsheet variable values within shell commands. Attackers can exploit this issue by crafting malicious file names in suggestion command directories, potentially leading to the execution of arbitrary commands under the victim's privileges. This significant issue underscores the need for users to ensure proper validation and sanitization of inputs to mitigate risks associated with unauthorized command execution.
Affected Version(s)
navi 0 <= 2.24.0
