{"id":"openSUSE-SU-2026:21675-1","summary":"Security update for broot","details":"This update for broot fixes the following issues:\n\nChanges in broot:\n\n- v1.59.0 (CVE-2026-72847 boo#1275994)\n  * new shell_command verb attribute: run a command through a shell (sh -c / cmd /C) so &&, ; and pipes work, without leaving broot - Fix #1145\n  * fix invalid official Mac binary (duplicate linked dylib) with new build chain - Fix #1194\n  * Sixel graphics support for image preview, auto-detected: works in iterm2, Windows Terminal 1.22+ and Sixel-capable Unix terminals (foot, mlterm, xterm built with Sixel, recent WezTerm). Kitty remains the preferred protocol when available. Note: this requires broot to be compiled with sixel feature (eg cargo install broot --features sixel) - Fix #568\n  * High-Res images in Rio terminal (detect it to enable the Kitty image protocol) - Fix #1179\n  * fix iTerm2 3.6.10 and later not displaying Hi-Res images, the version being compared as text\n  * fix content-exact match line number off-by-one when the match starts at the first byte of a line (broot jumped to the line above)\n  * new :no_action internal, doing nothing, which can be used to disable a key - Fix #328\n  * fix: detect a duplicate broot server name instead of silently overtaking the running server - Fix #1065\n  * fix preview transformers extension matching not working with double extensions such as .tar.gz - Fix #1195\n  * strip escape sequences from displayed names to prevent OSC injections - Fix #1188\n  * fall back to numeric uid/gid instead of ???? when the user or group name can't be resolved, which is always the case on statically linked musl builds - Fix #1075\n  * fix panic on a content regex matching the empty string at the end of a line ending with a control char (eg cr/$/ on a CRLF file)\n  * fix Windows paths (containing backslashes) being mangled by the launcher's eval when using :cd and similar; also fixes escaping of paths containing a single quote - Fix #1100\n  * fix br failing on Windows/PowerShell when the temp path contains a space (e.g. a space in the Windows username) - Fix #788\n  * JPEG XL images are no longer previewed: the decoder had out-of-bounds bugs and the fix needs a more recent rustc (if you need it, tell me and I'll try to make it opt-in)\n  * rustc minimal version changed from 1.83 to 1.85, and edition 2024\n\n- v1.58.0\n  * change the way possible verb completions are listed, making it more readable when there are more than what fits the screen\n  * fix argument of :select and :show being ignored in a --cmd sequence - Fix 1176\n\n- v1.57.0\n  * help: verb 'keys' and 'description' columns now searchable - Fix #1163\n  * fix :print_path / :print_relative_path adding a trailing empty line when printing a multi-item staging area - Fix #1062\n  * Skin: attributes (bold, underlined, etc.) of the \"selected_line\" entry now applied - Fix #1156\n  * if no Wezterm version is found, broot now assumes it's recent enough to support kitty protocol for image - Fix #509\n\n- v1.56.4\n  * fix compilation on non unix platforms (1.56.3 isn't available on those systems)\n\n- v1.56.3\n  * fix control characters sometimes remaining in the terminal after broot exit\n  * nushell: rename br module to avoid conflict in last nushell version - Fix #1138\n  * :open_stay on the staging area opens every staged file through the system opener - Fix #444\n\n- v1.56.2\n  * {file-root-relative} argument - Fix #1142\n  * fix :clear_stage (or other operations closing the stage panel) often closing broot - Fix #1143\n\n- v1.56.1\n  * fix a typo in a verb in default conf\n\n- v1.56.0\n  * impacted_panel verb argument, allows the effect of a verb to be on another panel (eg to scroll the preview panel without removing the focus from the tree) - Fix #1119\n  * focus_panel_left and focus_panel_right internals - Fix #1115\n  * Major Feature: merge staged files to issue a single command: when a verb argument has a space-separated or comma-separated flag, a single external command is run even when the selection is multiple - Fix #465 The default verbs.json file has an example of a zip verb building an archive from all staged files.\n\n- v1.55.0\n  * activate Kitty Graphics Protocol to display Hi-Res images in iTerm2\n  * Tokyo Night skin ( https://github.com/Canop/broot/blob/main/resources/default-conf/skins/tokyo-night.hjson )\n  * matches related to several name patterns joined with and/or in a composite pattern are merged instead of having just the first one shown\n  * nushell integration: switch $nu.temp-path to $nu.temp-dir - #1116\n\n- v1.54.0\n  * fix crash on rendering B&W images with Kitty image protocol\n  * don't match directories when a composite pattern has a content pattern, even negated (eg /js$/&!c/;: it's clear the user wants to match js files not containing a semicolon)\n\n- v1.53.0\n  * fix some cases of the verb not removed from the input on execution (with a risk of accidental double execution)\n  * add the :filesystems (short :fs) verb and state on windows (it was already present on linux and mac).\n  * improve the generation of preview pattern from a file tree pattern (i.e. going from /java$/&c/test to /test on opening a matching file in preview). With this change broot avoids filtering the preview when it shouldn't (eg when you searched /java$/|c/test) - See #1097\n  * display files whose name isn't valid UTF-8 (they were previously ignored)\n  * android executable is back to the official binary archive\n\n- v1.52.0\n  * auto_open_staging_area preference - Fix #1090\n  * search content of file target of symlink - Fix #1081\n  * fix nushell script (swapped logic for --listen and --listen-auto)\n  * return non-zero exit code on error\n\n- v1.51.0\n  * improved image rendering (both speed by using the zune-image library, and quality with bilinear interpolation)\n  * fix compilation broken by 1.50.0 on Android\n  * --listen-auto listens for commands on a random linux socket - Fix #1064\n  * when auto-completing, back-tab cycles in reverse order - Fix #1071\n\n- v1.50.0\n  * big text files now only partially loaded for initial display, remaining being done in background - Fix #1052\n  * better support of kitty image protocol over tmux, ssh or unknown terminals, with kitty_graphics_display option and $TMUX_NEST_COUNT env variable - see PR #1034\n  * \"trash\" compilation feature removed: trash related features are built depending on the platform\n  * build chain revised. Future official releases should include a Mac binary\n  * fix crash on double unstage of last entry in stage panel - fix #1057\n  * fallback to transparent background for text preview when the skin specifies nothing\n\n- v1.49.1\n  * watching made much more efficient (some deep changes won't lead to an automatic refresh which only impacts dir size)\n  * the name given with `--listen` is now provided to verb as the `{server-name}` verb argument\n\n- v1.49.0\n  * `:toggle_watch` internal, with `:watch` shortcut, bound by default to `alt-w`. When watching is active, the tree is refreshed whenever any directory/file, even deep, is changed - Fix #730\n  * fallback to a transparent background for images in image preview instead of a specific color - Fix #1040 - Thanks @letmeiiiin\n  * fix --server socket written at a non writable location on Android/termux - Fix #1045\n\n- v1.48.0\n  * Support for the 'Cmd' modifier in key shortcuts (the key is called 'Command', 'Super', 'Apple', 'Windows', depending on systems and users)\n  * \"filesystem\" features have been made available for Mac:\n      - the `:fs` screen, listing filesystems\n      - filesystem free space & total space displayed when size computations are requested\n      - device id displayed with `:toggle_device_id` (shortcut: \"dev\")\n  * Fix `.config/git/ignore` not being loaded on Mac - Fix #1032 - Thanks @9999years\n\n- v1.47.0\n  * text files with control chars were previously previewed as binary. They're now displayed as text with some '�' when needed - Fix #977\n  * files with ANSI escape codes (such as the one you would obtain with `dysk --color yes \u003e ansi.txt` can now be previewed with `:preview_tty` - Fix #1019\n  * first line of the tree is cropped (right aligned) when it doesn't fit\n\n- v1.46.5\n  * fix `:focus some/path` called in a command sequence always opening new panel - Fix #1014\n\n- v1.46.4\n  * support for keys F13 to F24 (if your system supports it)\n  * fix `:focus` with argument given in configuration going up one level when root is selected - Fix #1009\n  * fix `--max-depth` ignored when in `default_flags` - Fix #1013\n\n- v1.46.3\n  * fix broot waiting for events on internals like `:quit` - Fix #1006\n\n- v1.46.2\n  * fix broken nushell script (`--max-depth` again)\n\n- v1.46.1\n  * fix nushell script broken by new `--max-depth` argument\n\n- v1.46.0\n  * :set_max_depth \u003cnumber\u003e and :unset_max_depth\n  * clear cache when files are deleted in staging area\n  * recompute preview transform when source file changed since last preview\n\n- v1.45.1\n  * Fix compilation failing without `--locked`\n\n- v1.45.0\n  *  Fix total search impossible to redo after refresh\n  * With `refresh_after: false`, a verb configuration can request that the tree isn't refreshed after its execution\n\n- v1.44.7\n  * fix bad regex match position\n  * update resvg dependency to 0.44\n  * on `--server`, remove the existing socket if it already exists\n\n- v1.44.6\n  * fix .ignore files ignored when not in a git repository\n  * update git2 dependency to 0.20\n\n- v1.44.5\n  * no real change (just reverting a crate name to ease some packaging)\n\n- v1.44.4\n  * fix panic in preview on syntax coloring (when a sublime syntax isn't compatible with the regex engine)\n\n- v1.44.3\n  * removed default bindings on left and right keys. You may add them back by adding this to your verbs.hjson:\n    { key: \"left\", internal: \"back\" }\n    { key: \"right\", internal: \"open_stay\" }\n  * rustc minimal version changed from 1.76 to 1.79, which allows better performing image rendering\n  * remove dependency to onig, to allow compatibility with gcc 15\n\n- v1.44.2\n  * temp files created for kitty now erased on quitting or when too many of them have been written\n  * no longer panics when launched with BROOT_LOG=debug but the broot.log file can't be created\n  * fix user and group names displayed as \"????\" when coming from openldap\n\n- v1.44.1\n  * fix wrong position of IMEs (input method editors) popup - See #948\n  * improve querying the terminal for capabilities (prevent some escape chars from leaking)\n\n- v1.44.0\n  * `:focus_staging_area_no_open` internal, focus the staging area if it's already open, does nothing in other case\n  * fix some composite patterns with several operators and no parenthesis\n\n- v1.43.0\n  * 'Size' and 'Deletion date' columns in trash screen. This screen now supports the `:toggle_date`, `:toggle_size`, `:sort_by_date`, and `:sort_by_size` internals.\n  * new `:show` internal make the provided path visible and selected, adding lines to the tree if necessary, does nothing if the provided path is not a descendant of the current tree root (this part may change depending on feedback)\n\n- v1.42.0\n  * support of `.ignore` files with the same syntax than `.gitignore`. They have priority over `.gitignore` so that a personal `.ignore` file can override a shared `.gitignore` - See https://dystroy.org/broot/tree_view/#hidden-ignored-files\n  * `:toggle_ignore` internal, identical to `:toggle_git_ignore`, but with a clearer name so should be preferred\n  * the `panels` verb filter now works in most contexts (it was previously only checked on key events)\n  * many dependencies updated\n\n- v1.41.1\n  * allow compilation with rustc 1.76\n\n- v1.41.0\n  * Major Feature: :search_again\n    - ctrl-s now triggers `:search_again` which either\n    - brings back the last used search pattern, when no filtering pattern is active\n    - does a \"total search\" if a filtering pattern is active and the search wasn't complete\n  * Major Feature: internals changing panel widths\n    - `set_panel_width`, taking as parameter the index of the panel and the desired width\n    - `move_panel_divider`, taking as parameter the index of the divider and the desired change\n    - `ctrl-\u003c` is bound by default to `:move_panel_divider 0 -1`\n    - `ctrl-\u003e` is bound by default to `:move_panel_divider 0 1`\n    - See http://dystroy.org/broot/panels/#resize-panels\n  * Minor Changes:\n    - when git file infos are shown, and git ignored files aren't hidden, those files are flagged with a 'I'\n    - Remove .bak extension from content search exclusion list\n    - Update nerdfont and vscode icons\n    - `{initial-root}` verb argument\n\n- v1.40.0\n  * Major Feature: preview transformers\n    You can now define preview transformers to be applied before preview.\n    They allow for example previewing PDF or Office files, or beautifying JSON files.\n    Edit the `preview_transformers` array in your conf.hjson file.\n    See https://dystroy.org/broot/conf_file/#preview\n  * fix search on root\n  * fix some verb cycling problems\n\n- v1.39.2\n  * fix UNC paths being displayed on Windows (regression at 1.39.1)\n\n- v1.39.1\n  * fix high-resolution (kitty protocole) image broken in release mode\n  * canonicalize paths when focusing them (mostly useful when following links)\n  * a few minor internal optimizations\n","modified":"2026-08-30T13:00:05.983906541Z","published":"2026-08-28T21:08:53Z","related":["CVE-2026-72847"],"upstream":["CVE-2026-72847"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275994"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72847"}],"affected":[{"package":{"name":"broot","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/broot&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.59.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"broot":"1.59.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21675-1.json"}}],"schema_version":"1.9.0"}