Junglewise Threat Intelligence

CVE-2026-35363: uutils coreutils protection bypass in rm utility

CVE-2026-35363 · Severity: medium · CVSS 5.6 · Published 2026-07-06

Vendors: crates.io.

Executive brief

A vulnerability in the uutils coreutils 'rm' utility fails to protect the current directory from accidental deletion when trailing slashes are used in the command. While the tool normally prevents users from deleting the current directory ('.'), it fails to recognize variants like './' or './//', leading to the silent recursive deletion of all files and subdirectories. This can result in significant data loss, and a misleading error message may prevent users from realizing the damage in time to attempt data recovery.

Technical details

A path traversal and protection mechanism failure exists in the 'uu_rm' package of uutils coreutils. The 'clean_trailing_slashes' function normalizes paths like './//' to './', but the 'path_is_current_or_parent_directory' function only checks for literal '.' or '..' (and their absolute variants), failing to account for trailing slashes. Consequently, 'rm -rf ./' bypasses the safeguard that prevents deletion of the current directory, recursively deleting all contents before returning a misleading 'Invalid input' error. This issue was fixed in version 0.6.0 by updating the path validation logic to handle trailing-slash variants.

Affected products

  • uutils coreutils uu_rm < 0.6.0

Timeline

  • 2025-12-20: disclosed: Initial issue opened on GitHub
  • 2026-01-20: other: Security assessment prepared for Canonical by Zellic
  • 2026-05-30: patched: Fix published in version 0.6.0
  • 2026-07-06: advisory: GitHub Advisory published

References

Related threats