GHSA-jv2h-4p9v-wf5w
HIGHThe CVE-2026-47211 fix (0.39.0) added UNTRUSTEDENVDENYLIST to stop an untrusted project-directory .env from redirecting execution. The denylist was incomplete — several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, no review step):
- Affected
- <= 0.42.0
- Fixed in
- 0.42.1
- Weakness
- CWE-15
- Published
- 2026-06-19
- Source
- github