CVE-2026-103431High· 7.7▾ Twilightcolmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102601Low· 3.5Flysystem is an open source file storage library for PHP
CVE-2026-100867Low· 3.3spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt
CVE-2026-100866Low· 3.3onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection
CVE-2026-26149Critical· 9.0Microsoft Power Apps Desktop Client Spoofing Vulnerability
CVE-2026-72847Medium· 4.6broot renders each file and directory name in its interactive tree view exactly as read from the filesystem
CVE-2026-93421Medium· 5.3Mesop is a Python-based UI framework that allows users to build web applications