Intel

AIKIDO-2026-465495

uu_rm is vulnerable to Protection Mechanism Bypass

Protection Mechanism BypassGHSA-jqr3-q5m4-j7wx Published 4 days ago

66

Medium Risk

This Affects:

RUSTuu_rm
0.0.1 - 0.5.0
Fixed in 0.6.0
Are you affected? Scan for Free

TL;DR

rm accepts abbreviated spellings of --no-preserve-root, such as --n or --no, that GNU rm rejects. Passing those abbreviations disables the guard that refuses recursive operation on /. A user or script that passes such an option while running rm -r can delete the entire root filesystem. The fix rejects these abbreviations so only the full --no-preserve-root flag disables the guard.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run rm recursively while passing an abbreviated form of the --no-preserve-root flag.

Background info

uu_rm is vulnerable to Protection Mechanism Bypass in versions 0.0.1 - 0.5.0.

How to fix this

Upgrade the uu_rm library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform