CVE-2024-43402: What You Need to Know

On April 9th, 2024, the Rust Security Response WG disclosed CVE-2024-24576, where std::process::Command incorrectly escaped arguments when invoking batch files on Windows. We were notified that our fix for the vulnerability was incomplete, and it was possible to bypass the fix when the batch file name had trailing whitespace or periods (which are ignored and … Read more

Godot 4.4 Beta 2: The Highlights and Changelog

We’ve been keeping busy these past two weeks squashing the bugs that cropped up in 4.4 beta 1. Despite how much the previous snapshot added, it bears repeating that we have entered the 4.4 feature freeze, so our energy has been focused on addressing any new regressions or the aforementioned bugs. We’re still aiming for … Read more