Advisory #53
Titlebat arbitrary programs execution from current directory
CVE IDCVE-2021-36753
Vendorbat maintainers
Affected productbat
Affected versions=< v0.18.1
Vulnerability typeCWE-427 (Uncontrolled Search Path Element)
Descriptionbat before v0.18.1 allows attackers to trigger execution of arbitrary programs from the current working directory.
StatusFixed in v0.18.2
RecommendationUpdate to v0.18.2 or above.