#VU60674 OS Command Injection in zsh - CVE-2021-45444
Published: February 17, 2022
zsh
SourceForge
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to recursive PROMPT_SUBST expansion when processing malicious output. A remote attacker with ability to control the output can inject and execute arbitrary commands on the system with privileges on the current user.