GHSA-2m2p-wc26-4j7xMediumCVSS 5.0

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting...

Published
August 14, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.

🔗 References (5)