HIGH
denisidoro
CVE published 2026-09-27
CVE-2026-101032
CVE-2026-101032 is a high-severity vulnerability in the navi tool, which fails to properly escape cheatsheet variable values when substituting them into shell commands. This allows attackers to inject shell metacharacters through crafted file names in suggestion command directories, potentially leading to arbitrary command execution with victim privileges.