dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Byron
Byron dua-cli |
|
| Vendors & Products |
Byron
Byron dua-cli |
Thu, 13 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks. | |
| Title | dua-cli Terminal Escape Sequence Injection via Marked Paths | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T21:17:37.099Z
Reserved: 2026-08-12T18:19:17.024Z
Link: CVE-2026-73479
No data.
Status : Received
Published: 2026-08-13T22:17:26.747
Modified: 2026-08-13T22:17:26.747
Link: CVE-2026-73479
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:30:27Z
Weaknesses