sharkdp / fd

A simple, fast and user-friendly alternative to 'find'
Apache License 2.0
34.3k stars 816 forks source link

Update MSRV to 1.77.2 #1534

Closed tmccombs closed 7 months ago

tmccombs commented 7 months ago

Prior to this version, Command didn't properly escape command line arguments on windows.

Although, the risk of attacker controlled arguments passed through fd is relatively small, I think it is best to upgrade to a version that fixes this.

The biggest risk for users is probably running fd with --exec or --exec-batch on directories that contain files with names controlled by another party (for example a git repo that you cloned).

See: https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html Security: CVE-2024-24576