OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108744 (CVSS 7.3)

NVD · officialPublished Oct 11, 2026Risk 23/100

pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.

CVSS
7.3
AV:LocalAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source