HIGH
MinaSaad1
CVE published 2026-10-11
CVE-2026-108744
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:46.798Z and has not been modified since then. The vulnerability is an OS command injection in pbi-cli 3.10.1 through 3.12.0, specifically in the desktop_sync.py file. This allows attackers to lure victims into opening a Power BI project from a space-free path containing & to run commands wi [truncated]