GHSA-fq3w-p4fg-mw73
### Impact Affects: Anyone who generates the UNIX man pages in Fuji <= `0.8.0` build with the `dev` crate feature. Consequences: `/usr/share/man/man8` may be entirely removed & re-created without any of the previous entries. ### Patches At the time of writing, no new version has been released on crates.io, due to an unrelated CI/CD publishing issue. Due to the same unrelated publishing issue, no new GitHub Releases version has been released. ### Workarounds Do not run `fuji manual` on non-`dev` builds for versions <= `0.8.0`. ### Additional Information This bug results from development-only code being accidentally left in for release use. Previous versions of Fuji are still "safe" to use, provided that you do not run `fuji manual`. There is no malicious potential from this, it's just a major annoyance to accidentally remove all your sysadmin man pages.
Properties
- ghsa_id
- GHSA-fq3w-p4fg-mw73
- summary
- fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
- severity
- low
- cve_id
- GHSA-fq3w-p4fg-mw73
- is_ghsa_only
- true
- ghsa_published
- 2026-06-25T18:00:18Z
- source_url
- https://github.com/advisories/GHSA-fq3w-p4fg-mw73
- ghsa_updated
- 2026-06-25T18:00:20Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph