Zsh: Prompt Expansion Vulnerability A vulnerability has been discovered in Zsh, which can lead to execution of arbitrary code. zsh 2024-07-01 2024-07-01 833252 local 5.8.1 5.8.1

A shell designed for interactive use, although it is also a powerful scripting language.

Multiple vulnerabilities have been discovered in Zsh. Please review the CVE identifiers referenced below for details.

A vulnerability in prompt expansion could be exploited through e.g. VCS_Info to execute arbitrary shell commands without a user's knowledge.

There is no known workaround at this time.

All Zsh users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-shells/zsh-5.8.1"
CVE-2021-45444 graaff ajak