MEDIUMGo →
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Affected packages
- github.com/jandedobbeleer/oh-my-posh
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-fwjx-9p69-h25h
- https://github.com/JanDeDobbeleer/oh-my-posh/commit/edcf3c88f3fb582e84358b385c49d33d04c04224
- https://github.com/JanDeDobbeleer/oh-my-posh
- https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1
- https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0
Structured record: https://osv.dev/vulnerability/GHSA-fwjx-9p69-h25h
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta