Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Version 1.20.0 fixes the vulnerability.
History

Thu, 19 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Starship
Starship starship
Weaknesses CWE-78
CPEs cpe:2.3:a:starship:starship:*:*:*:*:*:*:*:*
Vendors & Products Starship
Starship starship

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-07-26T21:01:48.605Z

Updated: 2024-08-02T04:46:52.696Z

Reserved: 2024-07-22T13:57:37.137Z

Link: CVE-2024-41815

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.696Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-26T21:15:14.370

Modified: 2024-09-19T14:36:12.677

Link: CVE-2024-41815

cve-icon Redhat

No data.