Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-53534: JabRef can run arbitrary commands via Sublime Text integration

CVE-2026-53534 · published 19 days ago
Summary

If the built‑in web server in JabRef is turned on, a specially crafted request can cause the program to execute shell commands as the user when it tries to send citations to Sublime Text. This allows an attacker on the same machine to run any command they choose. Update JabRef to version 6.0‑alpha.6 or later, or keep the web server disabled, to stop the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– jabref jabref < 6.0-alpha.6
Ubuntu:16.04:LTS canonical jabref All versions
Original advisory text
JabRef CAYW Sublime Text integration permits operating-system command injection
JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published17 Sep 2026
Updated3 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta