CVE-2026-81698
opensslencrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like peppername containing shell commands that execute when users copy the printed CLI block into a shell.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81698.json, https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-gw2m-mj6q-59hc, https://nvd.nist.gov/vuln/detail/CVE-2026-81698, https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-shell-injection-via-info-command