`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './': Invalid input`. **Impact:** all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in `path_is_current_or_parent_directory`. **Remediation:** Acknowledged by Canonical; fixed in commit d0e5af23. --- _Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.60. Credit: Zellic._ _Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363_
Update uu_rm to 0.6.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanrm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection affects uu_rm (rust). Severity is medium. `rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './': Invalid input`. **Impact:** all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in `path_is_current_or_parent_directory`. **Remediation:** Acknowledged by Canonical; fixed in commit d0e5af23. --- _Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.60. Credit: Zellic._ _Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363_
AI coding agents often install or upgrade packages automatically in rust. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package |
|---|
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './': Invalid input`. **Impact:** all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in `path_is_current_or_parent_directory`. **Remediation:** Acknowledged by Canonical; fixed in commit d0e5af23. --- _Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.60. Credit: Zellic._ _Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363_
Update uu_rm to 0.6.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanrm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection affects uu_rm (rust). Severity is medium. `rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './': Invalid input`. **Impact:** all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in `path_is_current_or_parent_directory`. **Remediation:** Acknowledged by Canonical; fixed in commit d0e5af23. --- _Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.60. Credit: Zellic._ _Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363_
AI coding agents often install or upgrade packages automatically in rust. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package |
|---|
| Affected range |
|---|
| Fixed version |
|---|
| uu_rmrust | <0.6.0 | 0.6.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Affected range |
|---|
| Fixed version |
|---|
| uu_rmrust | <0.6.0 | 0.6.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard