CVE-2026-21882
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-273, CWE-269, CWE-250
- Published
- 2026-03-02
- Last modified
- 2026-03-12
Affected products
- AsfhtgkDavid theshit
Weakness type
Related vulnerabilities
- CVE-2026-58089 — hwpmc fails to detach PMCs during exec credential transitions
- CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-49421 — unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-44073 — seteuid failure ignored in auth modules
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails