CVE-2026-73505High· 7.8▾ TwilightOh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.2%
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/jandedobbeleer/oh-my-posh < 29.35.1Patched in:
github.com/jandedobbeleer/oh-my-posh 29.35.1Connected by shared product, vendor, weakness, or advisory.
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
CVE-2026-73506Medium· 6.1Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
GHSA-fwjx-9p69-h25hMedium· 6.1Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-54653High· 8.8`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
CVE-2026-54654High· 7.8`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field