PT-2026-71666 · Unknown · Oh-My-Posh
CVE-2026-73506
·
Published
2026-07-24
·
Updated
2026-09-04
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Oh My Posh versions prior to 29.35.1
Description
Terminal escape sequence injection occurs during prompt rendering because the
write(s rune) function in src/terminal/writer.go fails to remove C0/C1 terminal control characters—such as ESC, BEL, CSI, and OSC—from attacker-controlled current directory names and Git metadata. Affected metadata includes Commit.Subject, Commit.Author.Name, Commit.Author.Email, and RawUpstreamURL. This allows an attacker to overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal.Recommendations
Update to version 29.35.1.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oh-My-Posh