• nyan@sh.itjust.works
    link
    fedilink
    arrow-up
    16
    ·
    25 days ago

    Exactly. It’s Yet Another Privilege Escalation Vulnerability. Unless you’re dealing with a multiuser machine, the attacker first needs to use some other vuln to get into an unprivileged account. Without that additional vulnerability, this exploit is useless.

    • solrize@lemmy.ml
      link
      fedilink
      arrow-up
      13
      ·
      25 days ago

      some other vuln

      You mean like inveigling it into a pypi or npm or whatever package? Checks out.