---
id: CVE-2026-73479
title: >-
  dua-cli fails to filter terminal escape sequences when printing marked file
  paths after exiting the TUI interface
summary: >-
  dua-cli fails to filter terminal escape sequences when printing marked file
  paths after exiting the TUI interface. Attackers can craft file names
  containing OSC/CSI escape sequences that are interpreted by the terminal
  emulator when prin…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-116
vendor: Byron
product: dua-cli
affected:
  - dua-cli <= 2.41.1
published: '2026-08-13'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73479'
references:
  - url: 'https://github.com/Byron/dua-cli'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Byron/dua-cli/commit/b6e7cafd305c150834eb887e1de99bcdd3fca85d
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Byron/dua-cli/issues/365'
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00168
epssPercentile: 0.0535
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-14T16:29:01.347158Z'
ingestedAt: '2026-09-24T15:45:56.710Z'
---

## Overview

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
