CVE-2026-85082: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Maple Media Root Browser Classic
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.
AI Analysis
Technical Summary
Root Browser Classic 3.3.0 contains an OS command injection vulnerability (CWE-78) because it passes the path of a selected SQLite database directly to an OS shell without proper neutralization of special elements. This improper handling allows an attacker to inject arbitrary OS commands via crafted database paths. The CVSS 4.0 base score is 8.5, indicating high severity with local attack vector, low attack complexity, no privileges required, and user interaction needed. No known exploits in the wild or patches are currently reported.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary OS commands with the privileges of the application user, potentially leading to system compromise or data exposure. The vulnerability requires local access and user interaction, but no privileges or special conditions beyond that.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid opening untrusted SQLite database files with Root Browser Classic 3.3.0. Monitor vendor advisories for updates or patches addressing this vulnerability.
CVE-2026-85082: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Maple Media Root Browser Classic
Description
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.
CVSS v4.0
Score 8.5high
Affected software
Maple Media
Root Browser Classic
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Root Browser Classic 3.3.0 contains an OS command injection vulnerability (CWE-78) because it passes the path of a selected SQLite database directly to an OS shell without proper neutralization of special elements. This improper handling allows an attacker to inject arbitrary OS commands via crafted database paths. The CVSS 4.0 base score is 8.5, indicating high severity with local attack vector, low attack complexity, no privileges required, and user interaction needed. No known exploits in the wild or patches are currently reported.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary OS commands with the privileges of the application user, potentially leading to system compromise or data exposure. The vulnerability requires local access and user interaction, but no privileges or special conditions beyond that.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid opening untrusted SQLite database files with Root Browser Classic 3.3.0. Monitor vendor advisories for updates or patches addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Fluid Attacks
- Date Reserved
- 2026-09-02T22:03:15.544Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab5ba4ff7a7c54106fdbd6c
Added to database: 09/25/2026, 00:03:27 UTC
Last enriched: 09/25/2026, 00:17:39 UTC
Last updated: 09/25/2026, 01:55:56 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.