{"id":"CVE-2026-100866","summary":"onefetch through 2.28.1 Terminal Escape Sequence Injection","details":"onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.","modified":"2026-09-29T03:46:06.694820658Z","published":"2026-09-27T13:09:52.041Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-150"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100866.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100866.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100866"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/onefetch-through-2.28.1-terminal-escape-sequence-injection"},{"type":"REPORT","url":"https://github.com/o2sh/onefetch/issues/1828"},{"type":"PACKAGE","url":"https://github.com/o2sh/onefetch"},{"type":"ARTICLE","url":"https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/utils/info_field.rs#L43-L55"},{"type":"ARTICLE","url":"https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/version.rs#L33-L35"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/o2sh/onefetch","events":[{"introduced":"0"},{"fixed":"9beb80329cf2e5bd784270f668139f0bafb48e2b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.28.1"},{"fixed":"2.28.1"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["2.28.0","2.27.1","2.27.0","2.26.1","2.26.0","2.25.0","2.24.0","2.23.1","2.23.0","2.22.0","2.21.0","2.20.0","2.19.0","2.18.1","2.18.0","2.17.1","2.17.0","2.16.0","2.15.1","2.15.0","2.14.2","2.14.1","2.14.0","v2.13.2","v2.13.1","v2.13.0","v2.12.0","v2.11.0","v2.10.1","v2.10.0","v2.9.1","v2.9.0","v2.8.0","v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.1","v2.0.0","v1.7.0","v1.6.5","v1.6.0","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.0.5","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100866.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}