CVE-2026-73506: Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune
Summary
Oh My Posh, a tool that customizes command-line prompts across different systems, had a security flaw before version 29.35.1 where it didn't filter out terminal control characters (special codes like ESC that give commands to terminals) from file paths and Git information (version control metadata). This allowed attackers to inject terminal escape sequences (hidden commands that execute when the prompt is displayed), potentially letting them steal clipboard data, fake what appears on screen, change the window title, or crash the terminal.
Solution / Mitigation
This issue is fixed in version 29.35.1.
Vulnerability Details
6.1(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
local
low
none
required
August 13, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73506
First tracked: August 13, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%