criticalVulnerability
GHSA-f8h5-x737-x4xr
It depended on the `sha-rust` crate, which appeared to be attempting to steal credentials from local files.
Properties
- ghsa_id
- GHSA-f8h5-x737-x4xr
- severity
- critical
- summary
- `finch-rust` was removed from crates.io for malicious code
- cve_id
- GHSA-f8h5-x737-x4xr
- is_ghsa_only
- true
- ghsa_published
- 2026-02-06T20:58:19Z
- source_url
- https://github.com/advisories/GHSA-f8h5-x737-x4xr
- ghsa_updated
- 2026-02-06T20:58:21Z
Related Entities (2)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
AFFECTS (1)
→[Software]rust/finch-rust
Explore deeper with Ninja Signal's threat intelligence graph