PT-2026-65776 · Unknown · Diff-So-Fancy

·

CVE-2026-50642

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions diff-so-fancy (affected versions not specified)
Description The application fails to properly sanitize non-SGR terminal control sequences before outputting diff data. While ANSI SGR (Select Graphic Rendition) sequences are stripped, other control characters such as carriage return (r) and escape sequences like OSC (Operating System Command) and CSI (Control Sequence Introducer) are allowed to pass through. An attacker can embed these malicious sequences in filenames, diff metadata, or file content. When rendered in the terminal, this can lead to output manipulation, filename spoofing, terminal screen clearing, and clipboard injection, which may mislead users during code review or result in unintended command execution via clipboard hijacking.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50642

Affected Products

Diff-So-Fancy