CVE-2024-41815

HIGH

starship 1.0.0-1.19.0 - OS Command Injection via Custom Commands

Title source: llm
STIX 2.1

Description

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Version 1.20.0 fixes the vulnerability.

Scores

CVSS v3 7.4
EPSS 0.0046
EPSS Percentile 36.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-78
Status published
Products (2)
crates.io/starship 1.0.0 - 1.20.0crates.io
starship/starship 1.0.0 - 1.20.0
Published Jul 26, 2024
Tracked Since Feb 18, 2026