github.com/jandedobbeleer/oh-my-posh
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/jandedobbeleer/oh-my-poshpage 1 of 1
- CVE-2026-73505HIGHCVSS 7.8EG 7.8fixed in 29.35.1 or 29.35.1+incompatible, by version range2026-07-24
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function…
- CVE-2026-73506MEDIUMCVSS 6.1EG 6.1fixed in 29.35.1 or 29.35.1+incompatible, by version range2026-07-24
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names and Git metadata, including Commit.Subj…
Check whether github.com/jandedobbeleer/oh-my-posh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/jandedobbeleer/oh-my-posh CVEs against the assets you own.
Book a Demo →