OVERVIEW CVE-2026-35582 is an OS command injection vulnerability in Emissary, a P2P-based data-driven workflow engine, affecting versions 8.42.0 and earlier. The flaw exists in the Executrix.getCommand() function, which unsafely interpolates temporary file paths derived from IN_FILE_ENDING and OUT_FILE_ENDING configuration keys into shell command strings without proper escaping or input validation. This allows a place author with .cfg file write or modification permissions to inject arbitrary shell metacharacters and execute OS commands within the JVM process context. SEVERITY The vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) with a local attack vector requiring low privilege escalation but no user interaction. The attack surface is limited to users with configuration file authorship capabilities, though this represents a framework-level defect with no safe mitigation for downstream implementors. Successful exploitation results in complete compromise of confidentiality, integrity, and availability within the JVM process's security context. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation. No public exploit code is documented, and community attention remains minimal, as reflected by an EPSS score of 0.00054, indicating substantially lower exploitation probability compared to the general CVE population. The issue has been remediated in version 8.43.0, and organizations should prioritize patching to eliminate this framework-level defect.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.43.0CPE matchmatch criteria | cpe:2.3:a:nsa:emissary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.