๐Ÿ” CVE Alert

CVE-2026-21882

HIGH 8.4

theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0.

CWE CWE-273 CWE-269 CWE-250
Vendor asfhtgkdavid
Product theshit
Published Mar 2, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for asfhtgkdavid theshit

Be the first to know when new high vulnerabilities affecting asfhtgkdavid theshit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AsfhtgkDavid / theshit
< 0.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/AsfhtgkDavid/theshit/security/advisories/GHSA-2j3p-gqw5-g59j github.com: https://github.com/AsfhtgkDavid/theshit/commit/5293957b119e55212dce2c6dcbaf1d7eb794602a