PT-2026-71666 · Unknown · Oh-My-Posh

CVE-2026-73506

·

Published

2026-07-24

·

Updated

2026-09-04

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Oh My Posh versions prior to 29.35.1
Description Terminal escape sequence injection occurs during prompt rendering because the write(s rune) function in src/terminal/writer.go fails to remove C0/C1 terminal control characters—such as ESC, BEL, CSI, and OSC—from attacker-controlled current directory names and Git metadata. Affected metadata includes Commit.Subject, Commit.Author.Name, Commit.Author.Email, and RawUpstreamURL. This allows an attacker to overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal.
Recommendations Update to version 29.35.1.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73506
GHSA-FCRW-F7GG-6G9F
GHSA-FWJX-9P69-H25H
GO-2026-6111
OPENSUSE-SU-2026:21761-1

Affected Products

Oh-My-Posh