CWE-150— Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.— MITRE CWE catalog
89 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-150page 2 of 2
- CVE-2025-65082MEDIUMCVSS 6.5EG 6.52025-12-05
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. …
- CVE-2024-9774MEDIUMCVSS 6.5EG 6.52024-12-27
A vulnerability was found in python-sql where unary operators do not escape non-Expression.
- CVE-2023-40185MEDIUMCVSS 6.5EG 6.52023-08-23
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers t…
- CVE-2025-1692MEDIUMCVSS 6.3EG 6.32025-02-27
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted t…
- CVE-2026-73506MEDIUMCVSS 6.1EG 6.12026-07-24
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Subj…
- CVE-2026-6019MEDIUMCVSS 6.1EG 6.12026-04-22
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64…
- CVE-2025-23026MEDIUMCVSS 6.1EG 6.12025-01-13
jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or script attributes that include a Javascript template string (backticks) are subject t…
- CVE-2025-30089MEDIUMCVSS 5.4EG 5.42025-03-17
gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequences.
- CVE-2026-93421MEDIUMCVSS 5.3EG 5.32026-09-23
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report h…
- CVE-2026-64654MEDIUMCVSS 5.3EG 5.32026-08-06
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing term…
- CVE-2026-46739MEDIUMCVSS 5.3EG 5.32026-06-04
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. The update_stats (used fo…
- CVE-2026-46740MEDIUMCVSS 5.3EG 5.32026-05-26
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd …
- CVE-2026-23829MEDIUMCVSS 5.3EG 5.32026-01-19
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An at…
- CVE-2026-21439MEDIUMCVSS 5.3EG 5.32026-01-06
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., tha…
- CVE-2024-50349MEDIUMCVSS 4.7EG 4.72025-01-14
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using …
- CVE-2026-72847MEDIUMCVSS 4.6EG 4.62026-08-20
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_lin…
- CVE-2026-47090MEDIUMCVSS 4.6EG 4.62026-05-18
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded values, allowing attackers to inject ar…
- CVE-2025-64494MEDIUMCVSS 4.6EG 4.62025-11-08
Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for e…
- CVE-2026-73036MEDIUMCVSS 4.4EG 4.42026-08-11
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by embedding escape sequences in th…
- CVE-2026-73035MEDIUMCVSS 4.3EG 4.32026-08-10
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or reposi…
- CVE-2026-35651MEDIUMCVSS 4.3EG 4.32026-04-10
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approva…
- CVE-2025-1693LOWCVSS 3.9EG 3.92025-02-27
The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages…
- CVE-2023-39342LOWCVSS 3.6EG 3.62023-08-08
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's…
- CVE-2026-102601LOWCVSS 3.5EG 3.52026-09-29
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both fal…
- CVE-2026-45803LOWCVSS 3.5EG 3.52026-05-15
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using g…
- CVE-2026-100867LOWCVSS 3.3EG 3.32026-09-27
spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to mani…
- CVE-2026-100866LOWCVSS 3.3EG 3.32026-09-27
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version …
- CVE-2026-75483LOWCVSS 3.3EG 3.32026-08-17
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on e…
- CVE-2026-40505LOWCVSS 3.3EG 3.32026-04-16
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that …
- CVE-2024-28085LOWCVSS 3.3EG 3.32024-03-27
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences …
- CVE-2026-90773LOWCVSS 3.2EG 3.22026-09-13
procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line argumen…
- CVE-2023-30844LOWCVSS 3.0EG 3.02023-05-08
Mutagen provides real-time file synchronization and flexible network forwarding for developers. Prior to versions 0.16.6 and 0.17.1 in `mutagen` and prior to version 0.17.1 in `mutagen-compose`, Mutagen `list` and `monitor` commands are su…
- CVE-2021-25743LOWCVSS 3.0EG 3.02022-01-07
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
- CVE-2025-55193LOWCVSS 2.7EG 2.72025-08-13
Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unes…
- CVE-2024-58251LOWCVSS 2.5EG 2.52025-04-23
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
- CVE-2024-43785LOWCVSS 2.5EG 2.52024-08-22
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including …
- CVE-2026-82710LOWCVSS 2.3EG 2.32026-09-08
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rul…
- CVE-2026-82584LOWCVSS 2.3EG 2.32026-09-07
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation panel …
- CVE-2025-58160LOWCVSS 2.3EG 2.32025-08-29
tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input co…
Map vulnerabilities like CWE-150 to your infrastructure
EchelonGraph correlates every CVE — across CWE-150 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →