CVE-2024-58266: Comex Shlex

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

Affected products

  • Comex Shlex: before 1.2.1 (fixed in 1.2.1)

Published 2025-07-27. Last modified 2026-06-17.