What is CVE-2026-65611?
The nnn file manager fails to sanitize the path variable. An attacker can craft a directory name containing a single quote followed by shell syntax on a shared filesystem, removable media, or inside an archive, which leads to command execution when the victim uses batch copy or move operations within that directory. Users are advised to update nnn to the latest version and exercise caution when working with untrusted filesystems.
Azərbaycanca: nnn fayl meneceri istifadəçi tərəfindən daxil edilmiş yol (path) dəyişənini düzgün təmizləmir. Zərərli aktyor paylaşılan fayl sistemi, çıxarıla bilən media və ya arxiv daxilində xüsusi simvollar (tək dırnaq) ehtiva edən qovluq adı yaradaraq, qurban bu qovluğa daxil olub toplu kopyalama və ya daşıma əməliyyatı icra etdikdə öz əmrlərini işlədə bilər. İstifadəçilərə nnn proqramını ən son versiyaya yeniləmək və tanımadıqları mənbələrdən gələn fayl sistemlərində ehtiyatlı olmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ1
How is CVE-2026-65611 exploited in the nnn file manager?
An attacker crafts a directory name containing a single quote and shell syntax on a shared filesystem, removable media, or inside an archive. When the victim performs batch copy or move operations within that directory, the unsanitized path variable leads to command execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.