CVE-2026-103431: Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances
A flaw was found in collectl's colmux utility. colmux receives monitoring data from remote collectl instances over TCP port 2655 and renders it directly to the operator's terminal without neutralizing ANSI/VT100 terminal escape sequences. An unprivileged local user on any host monitored by collectl can embed terminal escape sequences in their process name (argv[0], read from /proc), which collectl (commonly run as root via its systemd unit, which has no User= directive) forwards unmodified to colmux. When an operator views this data via colmux, the injected sequences are interpreted by their terminal emulator, reliably allowing screen clearing and spoofed on-screen content. Depending on the operator's terminal emulator configuration, this could conditionally extend to clipboard manipulation or, if the operator pastes unseen clipboard content into a shell, command execution. The issue was fixed upstream in collectl 4.3.20.2/4.3.20.3 by sanitizing remote data at ingestion in colmux and at the source in collectl's formatit.ph, gated by a default-on sanitizer with a --rawescape opt-out flag for trusted networks. Fedora has shipped the fix (collectl-4.3.20.3, FEDORA-2026-71a9784a57).
Other sources
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
collectlto a version that resolves this vulnerability.Fixed in 4.3.20.3Patch FEDORA-2026-71a9784a57 - Configuration
Keep the default-on escape-sequence sanitizer enabled; use the --rawescape opt-out only on trusted networks.
collectl/colmux --rawescape = disabled