Advisory #49
Titleripgrep arbitrary programs execution from current directory
CVE IDCVE-2021-3013
Vendorripgrep maintainers
Affected productripgrep
Affected versions- 12.1.1
Vulnerability typeCWE-427 (Uncontrolled Search Path Element)
Descriptionripgrep before 13 allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
StatusFixed in v13
RecommendationUpdate to v13 or above