Duplicate Advisory: Multiple issues involving quote API in shlex
Low severity
GitHub Reviewed
Published
Jul 28, 2025
to the GitHub Advisory Database
•
Updated Jul 28, 2025
Withdrawn
This advisory was withdrawn on Jul 28, 2025
Description
Published by the National Vulnerability Database
Jul 27, 2025
Published to the GitHub Advisory Database
Jul 28, 2025
Reviewed
Jul 28, 2025
Withdrawn
Jul 28, 2025
Last updated
Jul 28, 2025
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-r7qv-8r2h-pg27. This link is maintained to preserve external references.
Original Description
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.
References