PatchSiren

frictionlessdata CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH frictionlessdata CVE published 2026-09-23

CVE-2026-93349

The CVE-2026-93349 vulnerability in the Frictionless package allows an attacker to execute arbitrary operating system commands as the user who explores a crafted Data Package descriptor. This is achieved by injecting shell metacharacters into resource path values within a datapackage.json descriptor, which are then passed unsanitized to os.system through a shell. To address this issue, users should update [truncated]