Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-286m-6pg9-v42v

Опубликовано: 28 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.2

Описание

Duplicate Advisory: Multiple issues involving quote API in shlex

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-r7qv-8r2h-pg27. This link is maintained to preserve external references.

Original Description

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

Пакеты

Наименование

shlex

rust
Затронутые версииВерсия исправления

< 1.3.0

1.3.0

3.2 Low

CVSS3

Дефекты

CWE-116

3.2 Low

CVSS3

Дефекты

CWE-116