starship
Activity
- Latest release
- 2mo ago
- Total releases
- 143
- Cadence
- ~25 days
- Last 12 months
- 6
Details
- License
- ISC
- First release
- May 23, 2019
| Version | Released | |
|---|---|---|
1.26.0
unknown
|
1.26.0
unknown
Dependencies (54)
+ 46 more |
|
1.25.1
unknown
|
1.25.1
unknown
Dependencies (54)
+ 46 more |
|
1.25.0
unknown
|
1.25.0
unknown
Dependencies (54)
+ 46 more |
|
1.24.2
unknown
|
1.24.2
unknown
Dependencies (54)
+ 46 more |
|
1.24.1
unknown
|
1.24.1
unknown
Dependencies (54)
+ 46 more |
|
1.24.0
unknown
|
1.24.0
unknown
Dependencies (54)
+ 46 more |
|
1.23.0
unknown
|
1.23.0
unknown
Dependencies (54)
+ 46 more |
|
1.22.1
unknown
|
1.22.1
unknown
Dependencies (53)
+ 45 more |
|
1.22.0
unknown
|
1.22.0
unknown
Dependencies (52)
+ 44 more |
|
1.21.1
unknown
|
1.21.1
unknown
Dependencies (52)
+ 44 more |
|
1.21.0
unknown
yanked
|
1.21.0
unknown
yanked
Dependencies (52)
+ 44 more |
|
1.20.1
unknown
|
1.20.1
unknown
Dependencies (53)
+ 45 more |
|
1.19.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.19.0
unknown
Dependencies (53)
+ 45 more |
|
1.18.2
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.18.2
unknown
Dependencies (53)
+ 45 more |
|
1.18.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.18.1
unknown
Dependencies (53)
+ 45 more |
|
1.17.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.17.1
unknown
Dependencies (53)
+ 45 more |
|
1.17.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.17.0
unknown
Dependencies (53)
+ 45 more |
|
1.16.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.16.0
unknown
Dependencies (53)
+ 45 more |
|
1.15.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.15.0
unknown
Dependencies (53)
+ 45 more |
|
1.14.2
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.14.2
unknown
Dependencies (53)
+ 45 more |
|
1.14.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.14.1
unknown
Dependencies (53)
+ 45 more |
|
1.13.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.13.1
unknown
Dependencies (53)
+ 45 more |
|
1.12.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.12.0
unknown
Dependencies (53)
+ 45 more |
|
1.11.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.11.0
unknown
Dependencies (54)
+ 46 more |
|
1.10.3
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.10.3
unknown
Dependencies (54)
+ 46 more |
|
1.10.2
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.10.2
unknown
Dependencies (54)
+ 46 more |
|
1.10.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.10.1
unknown
Dependencies (54)
+ 46 more |
|
1.10.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.10.0
unknown
Dependencies (53)
+ 45 more |
|
1.9.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.9.1
unknown
Dependencies (52)
+ 44 more |
|
1.8.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.8.0
unknown
Dependencies (52)
+ 44 more |
|
1.7.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.7.1
unknown
Dependencies (53)
+ 45 more |
|
1.7.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.7.0
unknown
Dependencies (53)
+ 45 more |
|
1.6.3
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.6.3
unknown
Dependencies (51)
+ 43 more |
|
1.6.2
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.6.2
unknown
Dependencies (51)
+ 43 more |
|
1.5.4
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.5.4
unknown
Dependencies (50)
+ 42 more |
|
1.4.2
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.4.2
unknown
Dependencies (50)
+ 42 more |
|
1.4.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.4.0
unknown
Dependencies (50)
+ 42 more |
|
1.3.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.3.0
unknown
Dependencies (48)
+ 40 more |
|
1.2.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.2.1
unknown
Dependencies (47)
+ 39 more |
|
1.2.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.2.0
unknown
Dependencies (47)
+ 39 more |
|
1.1.1
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.1.1
unknown
Dependencies (48)
+ 40 more |
|
1.1.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.1.0
unknown
Dependencies (48)
+ 40 more |
|
1.0.0
unknown
1 CVE
CVE-2024-41815
GHSA-vx24-x4mv-vwr5
RUSTSEC-2024-0446
Jul 26, 2024
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
7.4
/ 10
High
Local
High
None
None
Unchanged
High
High
High
DescriptionStarship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. Version 1.20.0 fixes the vulnerability. PoCHave some custom command which prints out information from a potentially untrusted/unverified source.
ImpactThis issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Fixed in
1.20.0
References
Updated Dec 22, 2025 · Source: OSV.dev |
1.0.0
unknown
Dependencies (48)
+ 40 more |
|
0.58.0
unknown
|
0.58.0
unknown
Dependencies (46)
+ 38 more |
|
0.57.0
unknown
|
0.57.0
unknown
Dependencies (46)
+ 38 more |
|
0.56.0
unknown
|
0.56.0
unknown
Dependencies (46)
+ 38 more |
|
0.55.0
unknown
|
0.55.0
unknown
Dependencies (45)
+ 37 more |
|
0.54.0
unknown
|
0.54.0
unknown
Dependencies (45)
+ 37 more |
|
0.53.0
unknown
|
0.53.0
unknown
Dependencies (45)
+ 37 more |
|
0.52.1
unknown
|
0.52.1
unknown
Dependencies (45)
+ 37 more |