CVE-2026-73479: dua-cli Terminal Escape Sequence Injection via Marked Paths
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73479?
The severity of CVE-2026-73479 is rated as medium with a score of 5.
What does CVE-2026-73479 exploit?
CVE-2026-73479 exploits the failure of dua-cli to filter terminal escape sequences when printing marked file paths.
What potential impacts does CVE-2026-73479 have?
CVE-2026-73479 could enable title spoofing, clipboard manipulation, and other malicious actions in a terminal emulator.
How can I mitigate CVE-2026-73479?
To mitigate CVE-2026-73479, ensure you are using the latest version of dua-cli that addresses this vulnerability.
Is my terminal emulator affected by CVE-2026-73479?
Any terminal emulator that interprets escape sequences could be affected by the exploitation of CVE-2026-73479.