PT-2025-31025 · Shlex+2 · Shlex+2
Published
2024-01-21
·
Updated
2025-10-14
·
CVE-2024-58266
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
shlex crate versions prior to 1.2.1
Description
The shlex crate before version 1.2.1 for Rust allows unquoted and unescaped instances of the { and xa0 characters, which may facilitate command injection.
Recommendations
Update the shlex crate to version 1.2.1 or later.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Suse
Shlex