No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Web-infra-dev
Web-infra-dev rsbuild |
|
| Vendors & Products |
Web-infra-dev
Web-infra-dev rsbuild |
Tue, 15 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed via child_process.exec(), but because encodeURI() does not encode dollar signs, parentheses, or semicolons, embedded shell metacharacters are evaluated by /bin/sh, enabling arbitrary command execution. | |
| Title | Rsbuild < 2.0.9 Command Injection via openBrowser() URL Handling | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T18:12:19.787Z
Reserved: 2026-05-29T22:17:43.223Z
Link: CVE-2026-10144
Updated: 2026-09-21T18:12:16.377Z
Status : Received
Published: 2026-09-15T22:16:55.387
Modified: 2026-09-21T19:17:03.683
Link: CVE-2026-10144
No data.
OpenCVE Enrichment
Updated: 2026-09-18T11:45:07Z