github.com/jandedobbeleer/oh-my-posh vulnerabilities
CVEs whose affected-version data names the github.com/jandedobbeleer/oh-my-posh package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-73506Medium· 6.1Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Su…
CVE-2026-73505High· 7.8Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…
GHSA-fwjx-9p69-h25hMedium· 6.1Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment