CVE-2026-73506Medium· 6.1▾ SunlitOh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
0.1% → 0.2%
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Subject, Commit.Author.Name, Commit.Author.Email, and RawUpstreamURL, without removing C0/C1 terminal control characters such as ESC, BEL, CSI, and OSC, allowing terminal escape sequence injection during prompt rendering that could overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal. This issue is fixed in version 29.35.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/jandedobbeleer/oh-my-posh < 29.35.1Patched in:
github.com/jandedobbeleer/oh-my-posh 29.35.1Connected by shared product, vendor, weakness, or advisory.
GHSA-fwjx-9p69-h25hMedium· 6.1Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
CVE-2026-73505High· 7.8Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
CVE-2026-54162Medium· 4.7Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
CVE-2026-90773Low· 3.2procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column