PT-2026-99537 · Unknown · Spaceship-Prompt

·

CVE-2026-100867

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions spaceship-prompt versions prior to 4.22.6
Description The software fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. This allows attackers to embed ANSI/OSC escape sequences—special codes used to control terminal formatting and behavior—within version fields of package manifests. Consequently, when a user enters the affected directory, the terminal output can be manipulated, window titles can be rewritten, or displayed text can be spoofed.
Recommendations Update spaceship-prompt to version 4.22.6 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100867

Affected Products

Spaceship-Prompt