5.9
CVSS V3
Status
Impact
This vulnerability is related to the 'rsa' dependency, of which atuin is already installing the most recent version (0.9.6). There is no release of 'rsa' today with a fix for this vulnerability. The RSA GitHub project repo is working on pre-releases, so a fix may be expected soon. Waiting for upstream (RSA) to cut a new release with a fix, and for atuin to consume.
Status