VulnSea

CWE-150

CVEs classified under CWE-150, newest first.

14 CVEsRSS

CVE-2026-90895High· 8.4
1w ago

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

TwilightMISP · MISPEPSS 0.15%via NVD
CVE-2026-90773Low· 3.2
1w ago

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line argum…

Sunlitdalance · procsEPSS 0.10%via NVD
CVE-2026-82710Low· 2.3
2w ago

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_r…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_r…

Sunlitash-project · usage_rulesEPSS 0.40%via NVD
CVE-2026-82584Low· 2.3
2w ago

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation pane…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation pane…

Sunlitash-project · igniterEPSS 0.30%via NVD
GHSA-8qx3-8gm5-9cj2High
4w ago

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

Twilightpickem · pickemvia GHSA
CVE-2026-54162Medium· 4.7
1mo ago

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI

Sunlitalexandre-daubois · github.com/alexandre-daubois/embervia GHSA
CVE-2026-73506Medium· 6.1
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…

Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.19%via NVD
CVE-2026-73414None
1mo ago

Shescape is a simple shell escape library for JavaScript

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escapeAll APIs on Windows with shell set to…

SunlitEPSS 0.52%via NVD
CVE-2026-72913High· 7.8
1mo ago

Kitty is a cross-platform GPU based terminal

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.27%via NVD
CVE-2026-64654Medium· 5.3
1mo ago

GitHub CLI (gh) is GitHub's official command line tool

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing te…

Sunlitcli · cliEPSS 0.75%via NVD
GHSA-w4hw-qcx7-56prCritical
2mo ago

Shescape: Shell injection via unescaped parentheses on Windows with CMD

Shescape: Shell injection via unescaped parentheses on Windows with CMD

Midnightshescape · shescapevia GHSA
GHSA-fwjx-9p69-h25hMedium· 6.1
2mo ago

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
CVE-2026-6019Medium· 6.1
5mo ago

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base…

Sunlitpython · pythonEPSS 0.21%via NVD
CVE-2024-56201High· 8.8
1y ago

Jinja has a sandbox breakout through malicious filenames

Jinja has a sandbox breakout through malicious filenames

Twilightjinja2 · jinja2EPSS 0.31%via OSV
CWE-150 vulnerabilities (CVEs) · VulnSea