CVE-2026-59111 describes an OS command injection vulnerability in the eObčanka-Identifikace application developed by Digitální a informační agentura (DIA) for macOS. The application registers a custom URL scheme (czeeopauth://) that allows parameterized application execution. Prior to version 3.6.0, URL parameters passed to a compiled AppleScript wrapper were concatenated without adequate sanitization, enabling OS command injection. An attacker could exploit this by crafting a malicious URL using the custom scheme to inject arbitrary OS commands. The vulnerability is classified under CWE as improper neutralization of special elements used in OS commands. The fix was introduced in version 3.6.0 of the application. Users are advised to update to version 3.6.0 or later to mitigate the risk.