What is CVE-2026-65612?
CVE-2026-65612 is a critical vulnerability in the nnn file manager that fails to sanitize the filename variable. An attacker can craft a filename containing a single quote and shell syntax, which, when the victim opens the file using preview-tabbed, leads to arbitrary command execution. It is strongly advised to update nnn immediately to mitigate this risk, especially on systems where shared filesystems, removable media, or archives are used.
Azərbaycanca: CVE-2026-65612, fayl adı dəyişənini sanitizə etməyən nnn fayl menecerində kritik boşluqdur. Təcavüzkar xüsusi hazırlanmış fayl adı (tək dırnaq və shell sintaksisi ilə) yerləşdirərək, istifadəçi həmin faylı preview-tabbed ilə açdıqda ixtiyari əmrlər icra edə bilər. Paylaşılan sistemlər, çıxarılabilən media və arxivlərdən yayıla bilən bu hücuma qarşı dərhal nnn-i yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What risk does CVE-2026-65612 pose in the nnn file manager?
This vulnerability allows an attacker to execute arbitrary commands by crafting a filename containing a single quote and shell syntax, which triggers when the victim opens the file using preview-tabbed.
What should I do to protect against CVE-2026-65612?
Immediately update nnn, especially if shared filesystems, removable media, or archives are used.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.