Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-53534: JabRef can run arbitrary commands via Sublime Text integration
CVE-2026-53534 · published 19 days ago
Summary
If the built‑in web server in JabRef is turned on, a specially crafted request can cause the program to execute shell commands as the user when it tries to send citations to Sublime Text. This allows an attacker on the same machine to run any command they choose. Update JabRef to version 6.0‑alpha.6 or later, or keep the web server disabled, to stop the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | jabref | jabref | < 6.0-alpha.6 |
| Ubuntu:16.04:LTS | canonical | jabref | All versions |
Original advisory text
JabRef CAYW Sublime Text integration permits operating-system command injection
JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.
References
- https://github.com/JabRef/jabref/releases/tag/v6.0-alpha.6 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53534... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-53534 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-53534 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-53534 Third Party Advisory
- https://github.com/JabRef/jabref/security/advisories/GHSA-m42c-cw93-p629 Third Party Advisory
- https://github.com/JabRef/jabref/commit/b8663fe58e6c87c3927cdb4eeb1f6934d7c3f1d2 Third Party Advisory
- https://github.com/JabRef/jabref/pull/15628 Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-78OS Command Injection
Timeline
Published17 Sep 2026
Updated3 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-53534 · NVD
CVE-2026-53534 · MITRE
CVE-2026-53534 · OSV
GHSA-m42c-cw93-p629 · GHSA
UBUNTU-CVE-2026-53534 · OSV
Track software like this
Free during beta