Command Injection Vulnerability in JabRef Desktop Application
CVE-2026-53534

7.5HIGH

Key Information:

Vendor

Jabref

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-53534?

A command injection vulnerability exists in JabRef, a desktop application designed for managing BibTeX and BibLaTeX libraries. When the built-in HTTP server is enabled in versions before 6.0-alpha.6, an external command can be injected through the GET /better-bibtex/cayw endpoint. This occurs because the application improperly handles user-supplied input, allowing crafted requests to execute arbitrary operating system commands. Specifically, the PushToSublimeText module concatenates unvalidated command prefixes with citation keys, leading to potential exploitation on Unix-like systems via ProcessBuilder. To mitigate risks, users must remain vigilant about keeping their application updated and avoid enabling the built-in server unless necessary.

Affected Version(s)

jabref < 6.0-alpha.6

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.