PT-2022-1769 · Zsh+11 · Zsh+11
Ryotak
·
Published
2022-02-12
·
Updated
2025-08-23
·
CVE-2021-45444
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
zsh versions prior to 5.8.1
Description
The issue is related to the recursive PROMPT SUBST expansion in zsh, allowing an attacker to achieve code execution if they control a command output inside the prompt. This can be demonstrated by a
%F argument.Recommendations
For versions prior to 5.8.1, update to zsh version 5.8.1 to resolve the issue. As a temporary workaround, consider restricting the use of the
%F argument in the prompt to minimize the risk of exploitation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Zsh