What is CVE-2026-73479?
CVE-2026-73479: dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, leading to potential title spoofing, clipboard manipulation, or other terminal-based attacks. Users should update dua-cli to the patched version and avoid scanning untrusted file systems.
Azərbaycanca: CVE-2026-73479: dua-cli aləti TUI interfeysindən çıxdıqdan sonra işarələnmiş fayl yollarını çap edərkən terminal escape sequence-lərini filtrasiya etmir. Bu boşluqdan istifadə edən hücumçular OSK/CSI escape sequence-ləri olan xüsusi fayl adları yaradaraq terminalda başlıq saxtakarlığı, clipboard manipulyasiyası kimi əməliyyatlar həyata keçirə bilər. dua-cli istifadəçiləri yenilənməni tətbiq etməli və etibarsız mənbələrdən skan etməkdən çəkinməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What operations can an attacker perform by exploiting CVE-2026-73479?
Attackers can conduct title spoofing and clipboard manipulation by embedding OSC/CSI escape sequences in crafted file names.
What should dua-cli users do to mitigate CVE-2026-73479?
Users should update dua-cli to the patched version and avoid scanning untrusted file systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.