CVE-2017-18205: Zsh Project Zsh
High severity, CVSS 8.1. EPSS: 2.1% chance of exploitation in the next 30 days.
In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.
Affected products
- Zsh Project Zsh: before 5.4 (fixed in 5.4)
Published 2018-02-27. Last modified 2026-06-17.