CVE-2026-53534: JabRef CAYW Sublime Text integration permits operating-system command injection

Published Sep 17, 2026
·
Updated

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter and CAYWQueryParams.getCommand() passes it through CAYWResource.getCitation() into PushToSublimeText.getCommandLine(). On Unix-like systems, PushToSublimeText combines this untrusted cite-command prefix and citation keys into a string executed through sh -c by ProcessBuilder without shell escaping. A client that can cause a localhost request with application=sublime can inject shell metacharacters and execute operating-system commands as the JabRef user when a valid Sublime Text command path is configured and the victim completes the CAYW selection dialog. The built-in server is disabled by default, so exploitation requires the victim to enable it or run jabsrv. This issue is fixed in version 6.0-alpha.6.

Affected Software

1 affected component
JabRef JabRef<6.0-alpha.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade JabRef to a version that resolves this vulnerability.

    Fixed in 6.0-alpha.6

Event History

Sep 17, 2026
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed?

The built-in HTTP server is disabled by default. Exposure requires that the user has enabled it or is running jabsrv, and has configured a valid Sublime Text command path.

2

What must an attacker do to trigger command execution?

An attacker must be able to cause a request to the localhost endpoint with application=sublime and a malicious command parameter. The victim must then complete the CAYW selection dialog; command execution occurs as the JabRef user on Unix-like systems.

3

What should be done if an immediate upgrade is not possible?

Disable JabRef's built-in HTTP server and do not run jabsrv. Removing or avoiding the configured Sublime Text command path also prevents the described execution path.

4

How can I determine whether I need the fix?

Systems running a version earlier than 6.0-alpha.6 are affected only if the built-in server or jabsrv is active. Check whether the CAYW Sublime Text integration has a valid Sublime Text command path configured.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203