ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.
{ "nvd_published_at": "2021-06-11T12:15:00Z", "github_reviewed_at": "2021-06-14T19:32:57Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-78" ] }