Back

HIGH

Rsbuild < 2.0.9 Command Injection via openBrowser() URL Handling

Published Sep 15, 2026

Description

Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed via child_process.exec(), but because encodeURI() does not encode dollar signs, parentheses, or semicolons, embedded shell metacharacters are evaluated by /bin/sh, enabling arbitrary command execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 26, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Sep 21, 2026
NVD
Status Received
Modified Sep 15, 2026
Red Hat
Severity n/a
Public date n/a