Product
Hashcat is vulnerable to argument injection when parsing restore files, potentially leading to arbitrary code execution if a user restores a malicious session file.