OS command injection in ripgrep
Critical severity
GitHub Reviewed
Published
Aug 5, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jun 11, 2021
Reviewed
Jun 14, 2021
Published to the GitHub Advisory Database
Aug 5, 2021
Last updated
Feb 3, 2023
ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
References