PT-2026-42204 · Crates.Io+1 · Rtk
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
RTK versions prior to 0.32.0
Description
RTK (Rust Token Killer) improperly trusts project-local configuration files by automatically loading
.rtk/filters.toml from the working directory with the highest priority and without notifying the user. This allows an attacker to place a malicious filter file in a repository to apply regex-based modifications, such as strip lines matching, to shell command output before it reaches the LLM context. Consequently, attackers can selectively suppress or alter command output, including file contents, diffs, and security scan results, potentially concealing malicious code during AI-assisted development or review without detection.Recommendations
Update to version 0.32.0.
Exploit
Fix
Untrusted Search Path
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rtk