UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function. Attackers can inject shell metacharacters into untrusted data such as usernames, process names, or filenames to execute arbitrary commands. Exploitation vectors include crafted evidence inputs, mounted images with hostile filenames, and tampered artifact definitions. Successful exploitation can result in remote code execution on the forensic analyst's host system during evidence processing. The vulnerability is particularly concerning as it targets security and forensic tools used by analysts. A fix was introduced in version 3.3.0 and is tracked via a GitHub commit and pull request. The issue has been documented by VulnCheck and assigned CVE-2026-41449.