Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54826 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. |
Github GHSA |
GHSA-r7qv-8r2h-pg27 | Multiple issues involving quote API in shlex |
Thu, 07 Aug 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comex
Comex shlex |
|
| CPEs | cpe:2.3:a:comex:shlex:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Comex
Comex shlex |
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | shlex: Shlex Command Injection Vulnerability | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Jul 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection. | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-28T15:03:56.004Z
Reserved: 2025-07-27T00:00:00.000Z
Link: CVE-2024-58266
Updated: 2025-07-28T15:03:50.290Z
Status : Analyzed
Published: 2025-07-27T22:15:25.707
Modified: 2025-08-07T15:18:56.680
Link: CVE-2024-58266
OpenCVE Enrichment
No data.
EUVD
Github GHSA