PT-2026-71665 · Unknown · Oh-My-Posh
CVE-2026-73505
·
Published
2026-07-24
·
Updated
2026-09-04
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oh My Posh versions prior to 29.35.1
Description
The
setStyle() function in src/segments/path.go passes pt.Path, which contains raw folder names, to template.Render. Because the function map exposes cmd, a directory name controlled by an attacker containing a Go template expression can lead to arbitrary operating system command execution as the current user when the prompt renders within that directory or its descendants. This is a template injection issue where untrusted input is processed by the template engine.Recommendations
Update to version 29.35.1.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oh-My-Posh