What is CVE-2026-66486?
GNU cpio improperly encodes or escapes output in its archive member listing functionality. When using `cpio -it`, member names are printed directly without quoting, which could allow an attacker to inject formatting characters or perform other injection attacks via crafted archive member names. Users should update to a patched version of cpio.
Azərbaycanca: GNU cpio utilitində "cpio -it" əmri ilə arxiv üzvləri siyahılanarkən, fayl adları çıxışa heç bir qaçış simvolu olmadan yazılır. Bu boşluqdan istifadə edən təcavüzkar, xüsusi hazırlanmış fayl adları vasitəsilə çıxışda formatlama və ya inyeksiya hücumları həyata keçirə bilər. Təsirə məruz qalan cpio versiyalarını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which command in GNU cpio is affected by CVE-2026-66486?
The vulnerability occurs when using the `cpio -it` command to list archive members, as file names are written to the output without any escaping.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.