ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
Link | Tags |
---|---|
https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md | third party advisory patch |
https://github.com/BurntSushi/ripgrep/blob/e48a17e1891e1ea9dd06ba0e48d5fb140ca7c0c4/CHANGELOG.md | third party advisory release notes |