CVE-2026-100866
LOW
NVD
CVSS Score
3.3
Severity
LOW
Published
Sep 27, 2026
Vendor
unknown
Description
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
References
- https://github.com/o2sh/onefetch
- https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/utils/info_field.rs#L43-L55
- https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/version.rs#L33-L35
- https://github.com/o2sh/onefetch/issues/1828
- https://www.vulncheck.com/advisories/onefetch-through-2.28.1-terminal-escape-sequence-injection