CWE-150
49 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-150page 1 of 1
- CVE-2003-0063HIGHCVSS 7.3EG 7.32003-03-03
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a fil…
- CVE-2020-6932CRITICALCVSS 10.0EG 9.82020-08-12
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arb…
- CVE-2021-25310HIGHCVSS 8.8EG 8.82021-02-02
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to …
- CVE-2021-25743LOWCVSS 3.0EG 3.02022-01-07
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
- CVE-2022-30123CRITICALCVSS 10.0EG 10.02022-12-05
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
- CVE-2023-26055CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The sam…
- CVE-2023-28446HIGHCVSS 8.8EG 8.82023-03-24
Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary program names without any ANSI filtering allows any malicious program to clear the first 2 lines of a `op_spawn_child` o…
- CVE-2023-30844LOWCVSS 3.0EG 3.02023-05-08
Mutagen provides real-time file synchronization and flexible network forwarding for developers. Prior to versions 0.16.6 and 0.17.1 in `mutagen` and prior to version 0.17.1 in `mutagen-compose`, Mutagen `list` and `monitor` commands are su…
- CVE-2023-3265CRITICALCVSS 9.8EG 9.82023-08-14
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printabl…
- CVE-2023-39342LOWCVSS 3.6EG 3.62023-08-08
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's…
- CVE-2023-40185MEDIUMCVSS 6.5EG 6.52023-08-23
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers t…
- CVE-2024-27936HIGHCVSS 8.8EG 8.82024-03-21
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno library, maliciously crafted permission request can show the spoofed permission prompt by in…
- CVE-2024-28085LOWCVSS 3.3EG 3.32024-03-27
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences …
- CVE-2024-32986CRITICALCVSS 9.6EG 9.62024-05-03
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines in…
- CVE-2024-33899HIGHCVSS 7.1EG 7.12024-04-29
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
- CVE-2024-36052HIGHCVSS 7.5EG 7.52024-05-21
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.
- CVE-2024-43785LOWCVSS 2.5EG 2.52024-08-22
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including …
- CVE-2024-47252HIGHCVSS 7.5EG 7.52025-07-10
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomL…
- CVE-2024-50349MEDIUMCVSS 4.7EG 4.72025-01-14
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using …
- CVE-2024-52005HIGHCVSS 8.8EG 8.82025-01-15
Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will…
- CVE-2024-52006HIGHCVSS 7.5EG 7.52025-01-14
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information b…
- CVE-2024-56201HIGHCVSS 8.8EG 8.82024-12-23
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless o…
- CVE-2024-58251LOWCVSS 2.5EG 2.52025-04-23
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
- CVE-2024-9774MEDIUMCVSS 6.5EG 6.52024-12-27
A vulnerability was found in python-sql where unary operators do not escape non-Expression.
- CVE-2025-0975HIGHCVSS 8.8EG 8.82025-02-28
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
- CVE-2025-15311HIGHCVSS 7.8EG 7.82026-02-05
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
- CVE-2025-1692MEDIUMCVSS 6.3EG 6.32025-02-27
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that evaluates arbitrary code. Control characters in the pasted t…
- CVE-2025-1693LOWCVSS 3.9EG 3.92025-02-27
The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages…
- CVE-2025-23026MEDIUMCVSS 6.1EG 6.12025-01-13
jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or script attributes that include a Javascript template string (backticks) are subject t…
- CVE-2025-25286CRITICALCVSS 9.8EG 9.82025-02-13
Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain c…
- CVE-2025-30089MEDIUMCVSS 5.4EG 5.42025-03-17
gurk (aka gurk-rs) through 0.6.3 mishandles ANSI escape sequences.
- CVE-2025-47284CRITICALCVSS 9.9EG 9.92025-05-19
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It c…
- CVE-2025-55193LOWCVSS 2.7EG 0.02025-08-13
Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unes…
- CVE-2025-55754CRITICALCVSS 9.6EG 9.62025-10-27
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console s…
- CVE-2025-58160LOWCVSS 2.3EG 0.02025-08-29
tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input co…
- CVE-2025-64494MEDIUMCVSS 4.6EG 4.62025-11-08
Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for e…
- CVE-2025-65082MEDIUMCVSS 6.5EG 6.52025-12-05
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. …
- CVE-2026-21439MEDIUMCVSS 5.3EG 5.32026-01-06
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., tha…
- CVE-2026-21521HIGHCVSS 7.4EG 7.42026-01-22
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
- CVE-2026-23829MEDIUMCVSS 5.3EG 5.32026-01-19
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An at…
- CVE-2026-25996CRITICALCVSS 9.8EG 9.82026-02-12
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sa…
- CVE-2026-26149CRITICALCVSS 9.0EG 9.02026-04-14
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
- CVE-2026-35651MEDIUMCVSS 4.3EG 4.32026-04-10
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approva…
- CVE-2026-40505LOWCVSS 3.3EG 3.32026-04-16
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that …
- CVE-2026-41526MEDIUMCVSS 6.5EG 6.52026-04-28
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applica…
- CVE-2026-45038HIGHCVSS 7.8EG 7.82026-05-15
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerab…
- CVE-2026-45803LOWCVSS 3.5EG 3.52026-05-15
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users view GitHub Actions workflow logs using g…
- CVE-2026-47090MEDIUMCVSS 4.6EG 4.62026-05-18
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded values, allowing attackers to inject ar…
- CVE-2026-6019MEDIUMCVSS 6.1EG 6.12026-04-22
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64…
Map vulnerabilities like CWE-150 to your infrastructure
EchelonGraph correlates every CVE — across CWE-150 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →