VDB
Sign up
CRITICAL9.8

GHSA-g4xg-fxmg-vcg5

OS command injection in ripgrep

Details

ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ripgrep
Introduced in: 0Fixed in: 13.0.0

Upgrade ripgrep to 13.0.0 or newer (ecosystem crates.io).

crates.io/grep-cli
Introduced in: 0Fixed in: 0.1.6

Upgrade grep-cli to 0.1.6 or newer (ecosystem crates.io).

References