CVE-2026-26982Disclosure(ghostty / ghostty)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell environments. This attack requires an attacker to convince the user to copy and paste or drag and drop malicious text. The attack requires user interaction to be triggered, but the dangerous characters are invisible in most GUI environments so it isn't trivially detected, especially if the string contents are complex. Fixed in Ghostty v1.3.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghostty

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ghostty

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 103-0903-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26982 Ghostty Terminal Emulator Arbitrary Command Execution via Pasted Control Characters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26982

    Post summary

    The text announces CVE-2026-26982, describing it as an arbitrary command execution flaw in the Ghostly Terminal Emulator triggered by pasted control characters, but provides no proof of exploit, patch, or active exploitation data.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26982 Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitr… https://www.cve.org/CVERecord?id=CVE-2026-26982

    Post summary

    A new CVE (CVE-2026-26982) affecting Ghostty terminal emulator is disclosed, noting that control characters (e.g., Ctrl+C) can be injected via pasted or dropped text, potentially enabling arbitrary code execution. No PoC, exploit, patch, or active exploitation information is provided.

    0000080
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appghosttyghostty---

Explore more