Bug 2515738 (CVE-2026-73480) - CVE-2026-73480 github.com/dundee/gdu: gdu: Terminal Injection via Unstripped Escape Sequences
Summary: CVE-2026-73480 github.com/dundee/gdu: gdu: Terminal Injection via Unstripped ...
Keywords:
Status: NEW
Alias: CVE-2026-73480
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2516048 2516049
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 21:21 UTC by OSIDB Bzimport
Modified: 2026-08-14 15:08 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-13 21:21:29 UTC
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.


Note You need to log in before you can comment on or make changes to this bug.