What is CVE-2026-73035?
A terminal escape sequence injection vulnerability was discovered in npm-check-updates up to version 23.0.2. An attacker can embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields, which execute when a developer runs the `ncu --format` command. All users should update to the version fixed in commit b554b84.
Azərbaycanca: npm-check-updates paketinin 23.0.2 versiyasına qədər olan versiyalarında terminal escape sequence injection zəifliyi aşkarlanıb. Təcavüzkar dependency-nin package.json faylındakı homepage və ya repository URL sahələrinə xüsusi terminal idarəetmə simvolları yerləşdirə bilər. Bu, tərtibatçı `ncu --format` əmrini işlədərkən işə düşür. Bütün istifadəçilər commit b554b84 ilə düzəldilmiş versiyaya yeniləməlidir.
FAQ2
Which versions of npm-check-updates are affected by CVE-2026-73035?
The vulnerability affects all versions up to 23.0.2.
How can an attacker exploit CVE-2026-73035?
An attacker can embed terminal control characters in a dependency's package.json homepage or repository URL fields.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.