Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Vulnerability Description
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Subject, Commit.Author.Name, Commit.Author.Email, and RawUpstreamURL, without removing C0/C1 terminal control characters such as ESC, BEL, CSI, and OSC, allowing terminal escape sequence injection during prompt rendering that could overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or disrupt the terminal. This issue is fixed in version 29.35.1.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Vulnerability Type
转义、元或控制序列转义处理不恰当
Vulnerability Title
Jan De Dobbeleer Oh My Posh 输入验证错误漏洞
Vulnerability Description
Jan De Dobbeleer Oh My Posh是Jan De Dobbeleer个人开发者的一款命令行提示符美化工具。 Jan De Dobbeleer Oh My Posh 29.35.1之前版本存在输入验证错误漏洞,该漏洞源于src/terminal/writer.go中的write(s rune)函数在输出攻击者控制的当前目录名和Git元数据时未移除C0/C1终端控制字符,导致终端转义序列注入,可能覆盖剪贴板、伪造提示符或屏幕、操纵窗口标题或中断终端。
CVSS Information
N/A
Vulnerability Type
N/A