Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89p7-7cq3-hhr2

Опубликовано: 06 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.6

Описание

rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection

rm -rf . is correctly refused, but clean_trailing_slashes normalizes ./// to ./ while path_is_current_or_parent_directory only matches ./.. (and /.//..), not ./ or ../. So rm -rf ./ recursively deletes the directory's contents and then prints a misleading cannot remove './': Invalid input.

Impact: all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in path_is_current_or_parent_directory.

Remediation: Acknowledged by Canonical; fixed in commit d0e5af23.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.60. Credit: Zellic.

Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363

Пакеты

Наименование

uu_rm

rust
Затронутые версииВерсия исправления

< 0.6.0

0.6.0

EPSS

Процентиль: 6%
0.00166
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-22
CWE-693

Связанные уязвимости

CVSS3: 5.6
ubuntu
4 месяца назад

A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fails to recognize equivalent paths with trailing slashes, such as ./ or .///. An accidental or malicious execution of rm -rf ./ results in the silent recursive deletion of all contents within the current directory. The command further obscures the data loss by reporting a misleading 'Invalid input' error, which may cause users to miss the critical window for data recovery.

CVSS3: 5.6
nvd
4 месяца назад

A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the utility correctly refuses to delete . or .., it fails to recognize equivalent paths with trailing slashes, such as ./ or .///. An accidental or malicious execution of rm -rf ./ results in the silent recursive deletion of all contents within the current directory. The command further obscures the data loss by reporting a misleading 'Invalid input' error, which may cause users to miss the critical window for data recovery.

CVSS3: 5.6
debian
4 месяца назад

A vulnerability in the rm utility of uutils coreutils allows the bypas ...

EPSS

Процентиль: 6%
0.00166
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-22
CWE-693