Critical severity9.8NVD Advisory· Published Aug 8, 2021· Updated Jun 17, 2026
CVE-2021-38196
CVE-2021-38196
Description
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
better-macrocrates.io | <= 1.0.4 | — |
Affected products
3- better-macro/better-macrodescription
- cpe:2.3:a:better-macro_project:better-macro:*:*:*:*:*:rust:*:*Range: <=2021-07-22
Patches
Vulnerability mechanics
References
5- rustsec.org/advisories/RUSTSEC-2021-0077.htmlnvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-79wf-qcqv-r22rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-38196ghsaADVISORY
- raw.githubusercontent.com/rustsec/advisory-db/main/crates/better-macro/RUSTSEC-2021-0077.mdnvdThird Party Advisory
- github.com/raycar5/better-macro/blob/24ff1702397b9c19bbfa4c660e2316cd77d3b900/src/lib.rsghsaWEB
News mentions
0No linked articles in our index yet.