---
id: CVE-2026-35363
aliases:
  - GHSA-89p7-7cq3-hhr2
title: >-
  rm: 'rm -rf ./' (and ./// variants) silently deletes current directory
  contents, bypassing dot protection
summary: >-
  rm: 'rm -rf ./' (and ./// variants) silently deletes current directory
  contents, bypassing dot protection
severity: medium
cvss: 5.6
cwe:
  - CWE-22
  - CWE-693
vendor: uu_rm
product: uu_rm
ecosystem: rust
affected:
  - uu_rm < 0.6.0
patched:
  - uu_rm 0.6.0
published: '2026-07-06'
updated: '2026-07-06'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-89p7-7cq3-hhr2'
references:
  - url: >-
      https://github.com/uutils/coreutils/security/advisories/GHSA-89p7-7cq3-hhr2
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35363'
  - url: 'https://github.com/uutils/coreutils/issues/9749'
  - url: 'https://github.com/advisories/GHSA-89p7-7cq3-hhr2'
tags:
  - ghsa
  - rust
epss: 0.00171
epssPercentile: 0.05747
ingestedAt: '2026-07-06T20:46:12.671Z'
---

## Overview

`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './': Invalid input`.

**Impact:** all files/subdirectories in the current directory are silently deleted; the misleading error makes users miss the recovery window. Recommendation: handle trailing-slash variants in `path_is_current_or_parent_directory`.

**Remediation:** Acknowledged by Canonical; fixed in commit d0e5af23.

---
_Reported by Zellic in the *uutils coreutils Program Security Assessment* (prepared for Canonical, Jan 20 2026), audited commit `3a07ffc5a9bd4c283e75afa548ba1f1957bad242`. Finding 3.60. Credit: Zellic._

_Upstream tracking issue: https://github.com/uutils/coreutils/issues/9749 · CVE-2026-35363_

## Affected packages

- `uu_rm < 0.6.0`

## Remediation

Upgrade to a patched release:

- `uu_rm 0.6.0`
