Ghostwire

CVE-2026-73480: gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers...

MEDIUM CVSS 0.0

Published: August 13, 2026 | Last Modified: August 13, 2026

Description

gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References