{"id":"GHSA-fq3w-p4fg-mw73","summary":"fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`","details":"### Impact\nAffects: Anyone who generates the UNIX man pages in Fuji \u003c= `0.8.0` build with the `dev` crate feature.\nConsequences: `/usr/share/man/man8` may be entirely removed & re-created without any of the previous entries.\n\n### Patches\nAt the time of writing, no new version has been released on crates.io, due to an unrelated CI/CD publishing issue.\nDue to the same unrelated publishing issue, no new GitHub Releases version has been released.\n\n### Workarounds\nDo not run `fuji manual` on non-`dev` builds for versions \u003c= `0.8.0`.\n\n### Additional Information\nThis bug results from development-only code being accidentally left in for release use.\nPrevious versions of Fuji are still \"safe\" to use, provided that you do not run `fuji manual`.\nThere is no malicious potential from this, it's just a major annoyance to accidentally remove all your sysadmin man pages.","modified":"2026-06-25T18:15:09.310360152Z","published":"2026-06-25T18:00:18Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-25T18:00:18Z","nvd_published_at":null,"cwe_ids":["CWE-489"]},"references":[{"type":"WEB","url":"https://github.com/EpicVon2468/fixurjavainstall/security/advisories/GHSA-fq3w-p4fg-mw73"},{"type":"PACKAGE","url":"https://github.com/EpicVon2468/fixurjavainstall"}],"affected":[{"package":{"name":"fixurjavainstall","ecosystem":"crates.io","purl":"pkg:cargo/fixurjavainstall"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.8.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fq3w-p4fg-mw73/GHSA-fq3w-p4fg-mw73.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}