Intel

AIKIDO-2026-749507

uucore is vulnerable to Code Injection

Code Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

55

Medium Risk

This Affects:

RUSTuucore
0.0.1 - 0.11.0
Fixed in 0.12.0
Are you affected? Scan for Free

TL;DR

The build script generates Rust source from localization strings without escaping their contents before embedding them in generated code. A translation string crafted by an untrusted contributor can therefore inject arbitrary Rust code that is compiled and executed as part of the build. The fix escapes generated locale content before it is written into the generated source.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you build the package from source with locale or translation content contributed by an untrusted party.

Background info

uucore is vulnerable to Code Injection in versions 0.0.1 - 0.11.0.

How to fix this

Upgrade the uucore library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform