---
id: CVE-2026-103431
title: >-
  colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal
  escape sequences in data received from remote collectl instances before
  displaying it, allowing a local user on a monitored host to inject escape
  sequences into the…
summary: >-
  colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal
  escape sequences in data received from remote collectl instances before
  displaying it, allowing a local user on a monitored host to inject escape
  sequences into the…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-150
product: collectl
affected:
  - collectl < 4.3.20.3
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T09:17:07.717'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103431'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-103431'
    label: patrick@puiterwijk.org
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2543974'
    label: patrick@puiterwijk.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T09:41:14.152Z'
---

## Overview

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
