CVE-2026-35197 PUBLISHED

Code injection in dye template expressions

Assigner: GitHub_M
Reserved: 01.04.2026 Published: 06.04.2026 Updated: 06.04.2026

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 6.6

Product Status

Vendor mattieb
Product dye
Versions
  • Version < 1.1.1 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE