VendorsFishshellfishany version
Vulnerabilities

Fishshell fish any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2014-2914
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
Published 2020-01-28 · Modified
9.8EPSS 0.032
CVE-2022-20001
Injection in fish
Published 2022-03-14 · Modified
7.8EPSS 0.015
CVE-2014-3219
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Published 2018-02-09 · Modified
7.8EPSS 0.004
CVE-2014-2906
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
Published 2020-01-28 · Modified
7.0EPSS 0.003
CVE-2014-3856
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
Published 2020-01-28 · Modified
7.0EPSS 0.003
CVE-2023-49284
Command substitution output can trigger shell expansion in fish shell
Published 2023-12-04 · Modified
6.6EPSS 0.005