ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
{ "affected_functions": [ "grep_cli::DecompressionReader::new" ] }