CVE-2014-2906: Fishshell Fish
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
Affected products
- Fishshell Fish: from 1.16.0, before 2.1.1 (fixed in 2.1.1)
Published 2020-01-28. Last modified 2026-06-17.