See how collectl compares to other vendors in security performance
A flaw was found in collectl's colmux utility. colmux receives monitoring data from remote collectl instances over TCP port 2655 and renders it directly to the operator's terminal without neutralizing ANSI/VT100 terminal escape sequences. An unprivileged local user on any host monitored by collectl can embed terminal escape sequences in their process name (argv[0], read from /proc), which collectl (commonly run as root via its systemd unit, which has no User= directive) forwards unmodified to colmux. When an operator views this data via colmux, the injected sequences are interpreted by their terminal emulator, reliably allowing screen clearing and spoofed on-screen content. Depending on the operator's terminal emulator configuration, this could conditionally extend to clipboard manipulation or, if the operator pastes unseen clipboard content into a shell, command execution. The issue was fixed upstream in collectl 4.3.20.2/4.3.20.3 by sanitizing remote data at ingestion in colmux and at the source in collectl's formatit.ph, gated by a default-on sanitizer with a --rawescape opt-out flag for trusted networks. Fedora has shipped the fix (collectl-4.3.20.3, FEDORA-2026-71a9784a57).
A flaw was found in collectl's colmux utility. colmux receives monitoring data from remote collectl instances over TCP port 2655 and renders it directly to the operator's terminal without neutralizing ANSI/VT100 terminal escape sequences. An unprivileged local user on any host monitored by collectl can embed terminal escape sequences in their process name (argv[0], read from /proc), which collectl (commonly run as root via its systemd unit, which has no User= directive) forwards unmodified to colmux. When an operator views this data via colmux, the injected sequences are interpreted by their terminal emulator, reliably allowing screen clearing and spoofed on-screen content. Depending on the operator's terminal emulator configuration, this could conditionally extend to clipboard manipulation or, if the operator pastes unseen clipboard content into a shell, command execution. The issue was fixed upstream in collectl 4.3.20.2/4.3.20.3 by sanitizing remote data at ingestion in colmux and at the source in collectl's formatit.ph, gated by a default-on sanitizer with a --rawescape opt-out flag for trusted networks. Fedora has shipped the fix (collectl-4.3.20.3, FEDORA-2026-71a9784a57).