powerlevel10k Control Character Injection via package.json Version
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.8epss 0.1%
probabilidad de explotación
0.1%top 98% de las CVE
explotación observada
noninguna fuente lo reporta
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
romkatv · powerlevel10kReferencias
https://github.com/romkatv/powerlevel10khttps://github.com/romkatv/powerlevel10k/blob/master/internal/p10k.zshhttps://github.com/romkatv/powerlevel10k/commit/58e13d16a50e1d6908e39e20a670896808ccf350https://github.com/romkatv/powerlevel10k/issues/2961https://www.vulncheck.com/advisories/powerlevel10k-control-character-injection-via-package-json-version