Bug 2515399 (CVE-2026-73505) - CVE-2026-73505 github.com/jandedobbeleer/oh-my-posh: Oh My Posh: Arbitrary command execution via template injection in directory names
Summary: CVE-2026-73505 github.com/jandedobbeleer/oh-my-posh: Oh My Posh: Arbitrary co...
Keywords:
Status: NEW
Alias: CVE-2026-73505
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2516075
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 15:51 UTC by OSIDB Bzimport
Modified: 2026-08-14 16:12 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-13 15:51:22 UTC
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1.


Note You need to log in before you can comment on or make changes to this bug.