CVE-2026-73480 PUBLISHED

gdu Terminal Injection via Unstripped Escape Sequences

Assigner: VulnCheck
Reserved: 12.08.2026 Published: 13.08.2026 Updated: 14.08.2026

gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor dundee
Product gdu
Versions Default: affected
  • affected from 0 to fe605ec (excl.)

Credits

  • George Chen reporter

References

Problem Types

  • Improper Encoding or Escaping of Output CWE