CVE-2026-73479
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Summary
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Byron | dua-cli | 0 <= 2.41.1 | affected |
Weaknesses
- CWE-116: Improper Encoding or Escaping of Output
References
- https://github.com/Byron/dua-cli/issues/365
- https://github.com/Byron/dua-cli
- https://github.com/Byron/dua-cli/commit/b6e7cafd305c150834eb887e1de99bcdd3fca85d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.