CVE-2026-90773 PUBLISHED

procs through 0.14.12 Terminal Escape Sequence Injection via Command

Assigner: VulnCheck
Reserved: 13.09.2026 Published: 13.09.2026 Updated: 13.09.2026

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CVSS Score: 2.4

Product Status

Vendor dalance
Product procs
Versions Default: unaffected
  • affected from 0 to 0.14.12 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Improper Neutralization of Escape, Meta, or Control Sequences CWE