HIGH
frictionlessdata
CVE published 2026-09-23
CVE-2026-93349
The CVE-2026-93349 vulnerability in the Frictionless package allows an attacker to execute arbitrary operating system commands as the user who explores a crafted Data Package descriptor. This is achieved by injecting shell metacharacters into resource path values within a datapackage.json descriptor, which are then passed unsanitized to os.system through a shell. To address this issue, users should update [truncated]