No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rtk-ai
Rtk-ai rtk |
|
| Vendors & Products |
Rtk-ai
Rtk-ai rtk |
Wed, 24 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constructs that Bash treats as command execution boundaries or nested execution. As a result, a command beginning with an allowed prefix such as git could hide a second command behind one of these constructs. rtk rewrite returned exit code 0, causing the Claude hook to emit permissionDecision: "allow". The rewritten command still contained the hidden command, so it ran without the user confirmation or denial that the permission rules were intended to enforce. This vulnerability is fixed in 0.42.2. | |
| Title | rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separators | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-24T14:30:40.984Z
Reserved: 2026-06-15T19:04:14.456Z
Link: CVE-2026-54555
Updated: 2026-06-24T14:30:32.307Z
Status : Deferred
Published: 2026-06-23T20:16:49.737
Modified: 2026-06-25T20:18:11.603
Link: CVE-2026-54555
No data.
OpenCVE Enrichment
Updated: 2026-06-24T16:05:42Z