CVE-2026-75483
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.
Schwachstellenklasse
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.
Quellen
- https://github.com/romkatv/powerlevel10k
- https://github.com/romkatv/powerlevel10k/blob/master/internal/p10k.zsh
- https://github.com/romkatv/powerlevel10k/commit/58e13d16a50e1d6908e39e20a670896808ccf350
- https://github.com/romkatv/powerlevel10k/issues/2961
- https://www.vulncheck.com/advisories/powerlevel10k-control-character-injection-via-package-json-version
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.