Skip to content
VulniPulse
Medium6.1Red Hat Linux

Medium [CVE-2026-73506] Terminal escape sequence injection via unsanitized prompt data

This medium-severity Red Hat Linux advisory covers CVE-2026-73506.

CVE-2026-73506 Published Aug 13, 2026Updated by vendor Aug 13, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.

Subject, Commit. Author.

Name, Commit.

Email, and RawUpstreamURL, without removing C0/C1 terminal control characters such as ESC, BEL, CSI, and OSC, allowing terminal escape sequence injection during prompt rendering that could overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal. This issue is fixed in version 29.35.1.

A flaw was found in Oh My Posh, a customizable terminal prompt renderer. Oh My Posh is not shipped in any Red Hat product.

It is available in Fedora as a community package. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).

Weakness: CWE-791.

Affected versions
  • < 29.35.1

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Fixed versions
  • 29.35.1

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Update to Oh My Posh version 29.35.1 or later. As a workaround, avoid navigating to untrusted git repositories or directories with untrusted names while using Oh My Posh as your prompt renderer.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.