PT-2026-65776 · Unknown · Diff-So-Fancy
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
diff-so-fancy (affected versions not specified)
Description
The application fails to properly sanitize non-SGR terminal control sequences before outputting diff data. While ANSI SGR (Select Graphic Rendition) sequences are stripped, other control characters such as carriage return (
r) and escape sequences like OSC (Operating System Command) and CSI (Control Sequence Introducer) are allowed to pass through. An attacker can embed these malicious sequences in filenames, diff metadata, or file content. When rendered in the terminal, this can lead to output manipulation, filename spoofing, terminal screen clearing, and clipboard injection, which may mislead users during code review or result in unintended command execution via clipboard hijacking.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Diff-So-Fancy