CVE-2026-73036: Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt
mediumvulnerability
security
Summary
Bash-it version 3.2.0 has a vulnerability where a malicious pyproject.toml file can inject terminal escape sequences (special codes that control terminal behavior) into the command prompt. When a user enters a directory with this malicious file, the unfiltered content gets added to the prompt without removing these control characters, causing the terminal to execute unwanted commands every time the prompt appears.
Vulnerability Details
CVSS Score
4.4(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
local
Attack Complexity
low
Privileges Required
none
User Interaction
required
Disclosure Date
August 11, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrity
Taxonomy References
CWE (Weakness Type)
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73036
First tracked: August 11, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 72%