GHSA-89p7-7cq3-hhr2

Suggest an improvement
Source
https://github.com/advisories/GHSA-89p7-7cq3-hhr2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-89p7-7cq3-hhr2/GHSA-89p7-7cq3-hhr2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-89p7-7cq3-hhr2
Aliases
  • CVE-2026-35363
Published
2026-07-06T20:20:56Z
Modified
2026-07-06T20:31:25.632444868Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L CVSS Calculator
Summary
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
Details

rm -rf . is correctly refused, but clean_trailing_slashes normalizes ./// to ./ while path_is_current_or_parent_directory only matches ./.. (and /.//..), not ./ or ../. So rm -rf ./ recursively deletes the directory's contents and then prints a misleading cannot remove './': Invalid input.

Impact: all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in path_is_current_or_parent_directory.

Remediation: Acknowledged by Canonical; fixed in commit d0e5af23.


Reported by Zellic in the uutils coreutils Program Security Assessment (prepared for Canonical, Jan 20 2026), audited commit 3a07ffc5a9bd4c283e75afa548ba1f1957bad242. Finding 3.60. Credit: Zellic.

Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 ยท CVE-2026-35363

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-693"
    ],
    "severity": "MODERATE",
    "github_reviewed_at": "2026-07-06T20:20:56Z",
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

crates.io / uu_rm

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-89p7-7cq3-hhr2/GHSA-89p7-7cq3-hhr2.json"