<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T06:21:10.108596+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-58266</id>
    <title>CVE-2024-58266</title>
    <updated>2026-10-10T06:21:10.110251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> comex shlex</p>
<p>The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-58266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27</id>
    <title>GHSA-r7qv-8r2h-pg27 — Multiple issues involving quote API in shlex</title>
    <updated>2026-10-10T06:21:10.110322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: shlex</p>
<p>## Issue 1: Failure to quote characters</p>
<p>Affected versions of this crate allowed the bytes `{` and `\xa0` to appear unquoted and unescaped in command arguments.</p>
<p>If the output of `quote` or `join` is passed to a shell, then what should be a single command argument could be interpreted as multiple arguments.</p>
<p>This does not *directly* allow arbitrary command execution (you can't inject a command substitution or similar).  But depending on the command you're running, being able to inject multiple arguments where only one is expected could lead to undesired consequences, potentially including arbitrary command execution.</p>
<p>The flaw was corrected in version 1.2.1 by escaping additional characters. Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if desired.</p>
<p>Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or output.</p>
<p>(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is problematic because it's treated as a word separator in [specific environments][solved-xa0].)</p>
<p>## Issue 2: Dangerous API w.r.t. nul bytes</p>
<p>Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote` and `try_join`, which behave the same except that they have `Result` return type, returning `Err` if the input contains nul bytes.</p>
<p>Strings containing nul bytes generally cannot be used in Unix command arguments or environment variables, and most shells cannot handle nul bytes even internally.  If you try to pass one anyway, then the resu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27"/>
  </entry>
</feed>
