Bug 2508367 (CVE-2026-50642) - CVE-2026-50642 diff-so-fancy: diff-so-fancy: Terminal escape injection allows command execution
Summary: CVE-2026-50642 diff-so-fancy: diff-so-fancy: Terminal escape injection allows...
Keywords:
Status: NEW
Alias: CVE-2026-50642
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2508640 2508641
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 11:01 UTC by OSIDB Bzimport
Modified: 2026-07-29 20:15 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-29 11:01:21 UTC
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escape sequences (e.g., OSC, CSI), to pass through unsanitized.

An attacker can embed malicious control sequences in filenames, diff metadata, or file content that are rendered directly in the terminal during diff viewing. This can lead to output manipulation, including filename spoofing, terminal screen clearing, and clipboard injection via supported escape sequences.

Successful exploitation may mislead users during code review, alter terminal state, or result in unintended command execution through clipboard hijacking.

This issue has been fixed in the commit 9c81294


Note You need to log in before you can comment on or make changes to this bug.