Planetargon's vulnerability footprint centers on Oh My Zsh, a widely adopted shell configuration framework that extends bash and zsh environments, with observed exposure centered on OS command injection and code injection weaknesses arising from the handling of user input and shell metacharacters. Treat this as a focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Planetargon over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3727CRITICAL # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some p | Nov 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-3769CRITICAL # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All | Nov 30, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-3726CRITICAL # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh M | Nov 30, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-3725HIGH Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsa | Nov 30, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-3934HIGH ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command | Nov 12, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Planetargon.
Media articles that mention a CVE ID that affects a product developed by Planetargon — matched by CVE ID, not by vendor name.