What is CVE-2026-50187?
This vulnerability exists in the Oh My Zsh dotenv plugin. When changing into a directory containing a `.env` file, the `ZSH_DOTENV_FILE` is passed to `source`, allowing execution of syntactically valid shell commands from the file. Versions prior to 2026-05-28 are affected; updating the plugin is recommended to mitigate the risk.
Azərbaycanca: Bu zəiflik Oh My Zsh dotenv plaginində aşkarlanıb. `.env` faylı olan qovluğa keçid zamanı `ZSH_DOTENV_FILE` vasitəsilə mənbəyə əmr ötürülür və bu, `source` əmri ilə shell əmrlərinin icrasına səbəb ola bilər. 2026-05-28-dən əvvəlki versiyalar təsirlənir; təhlükəsizlik üçün plaqini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which plugin is affected by CVE-2026-50187?
This vulnerability exists in the Oh My Zsh dotenv plugin.
How can this vulnerability in the Oh My Zsh dotenv plugin be exploited?
When changing into a directory containing a `.env` file, the `ZSH_DOTENV_FILE` is passed to `source`, allowing execution of syntactically valid shell commands.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.