{"id":"GHSA-fq3w-p4fg-mw73","aliases":[],"url":"https://o3.security/vulnerability/GHSA-fq3w-p4fg-mw73","summary":"fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`","details":"### Impact\nAffects: Anyone who generates the UNIX man pages in Fuji <= `0.8.0` build with the `dev` crate feature.\nConsequences: `/usr/share/man/man8` may be entirely removed & re-created without any of the previous entries.\n\n### Patches\nAt the time of writing, no new version has been released on crates.io, due to an unrelated CI/CD publishing issue.\nDue to the same unrelated publishing issue, no new GitHub Releases version has been released.\n\n### Workarounds\nDo not run `fuji manual` on non-`dev` builds for versions <= `0.8.0`.\n\n### Additional Information\nThis bug results from development-only code being accidentally left in for release use.\nPrevious versions of Fuji are still \"safe\" to use, provided that you do not run `fuji manual`.\nThere is no malicious potential from this, it's just a major annoyance to accidentally remove all your sysadmin man pages.","published":"2026-06-25T18:00:18Z","modified":"2026-06-25T18:15:09.679175008Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"fixurjavainstall","fixedVersion":"0.8.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/EpicVon2468/fixurjavainstall/security/advisories/GHSA-fq3w-p4fg-mw73"},{"type":"PACKAGE","url":"https://github.com/EpicVon2468/fixurjavainstall"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T18:15:09.679175008Z"}}