{"data":{"id":"f58dbd12-a015-4183-862d-389a28076708","title":"GHSA-g7f6-rxc4-qhph: Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint","summary":"A bug in Mesop's CSP reporting endpoint (a service that logs Content Security Policy violations) allows unauthenticated attackers to send specially crafted requests containing ANSI escape sequences (special characters that control how text appears in terminals). When these sequences are logged and displayed in a terminal, they can manipulate the output to hide real security warnings, display fake messages, or mislead administrators reviewing logs.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-g7f6-rxc4-qhph","publishedAt":"2026-09-23T19:01:05.000Z","cveId":"CVE-2026-93421","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["mesop@<= 1.3.3 (fixed: 1.3.4)"],"affectedVendors":["Google"],"affectedVendorsRaw":["Google Mesop"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-09-23T19:01:05.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}