Medium [CVE-2026-73506] Terminal escape sequence injection via unsanitized prompt data
This medium-severity Red Hat Linux advisory covers CVE-2026-73506.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.
Subject, Commit. Author.
Name, Commit.
Email, and RawUpstreamURL, without removing C0/C1 terminal control characters such as ESC, BEL, CSI, and OSC, allowing terminal escape sequence injection during prompt rendering that could overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal. This issue is fixed in version 29.35.1.
A flaw was found in Oh My Posh, a customizable terminal prompt renderer. Oh My Posh is not shipped in any Red Hat product.
It is available in Fedora as a community package. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Weakness: CWE-791.
- < 29.35.1
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- 29.35.1
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Update to Oh My Posh version 29.35.1 or later. As a workaround, avoid navigating to untrusted git repositories or directories with untrusted names while using Oh My Posh as your prompt renderer.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.