Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-3727 | # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection. Given that they're an external API, it's not possible to know if the quotes are safe to use. **Fixed in**: [72928432](https://github.com/ohmyzsh/ohmyzsh/commit/72928432). **Impacted areas**: - `rand-quote` plugin (`quote` function). - `hitokoto` plugin (`hitokoto` function). NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-3934 | ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command NVD description · AI analysis pending | 7.5 | <1% |
| — |