
CVE-2026-100866 onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection.… https://www.cve.org/CVERecord?id=CVE-2026-100866
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-100866 onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection.… https://www.cve.org/CVERecord?id=CVE-2026-100866