PT-2026-71665 · Unknown · Oh-My-Posh

CVE-2026-73505

·

Published

2026-07-24

·

Updated

2026-09-04

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oh My Posh versions prior to 29.35.1
Description The setStyle() function in src/segments/path.go passes pt.Path, which contains raw folder names, to template.Render. Because the function map exposes cmd, a directory name controlled by an attacker containing a Go template expression can lead to arbitrary operating system command execution as the current user when the prompt renders within that directory or its descendants. This is a template injection issue where untrusted input is processed by the template engine.
Recommendations Update to version 29.35.1.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73505
GHSA-6XJ8-QV9J-XCJQ
GO-2026-6108
OPENSUSE-SU-2026:21761-1

Affected Products

Oh-My-Posh