GHSA-g7f6-rxc4-qhph: Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Summary
A bug in Mesop's CSP reporting endpoint (a service that logs Content Security Policy violations) allows unauthenticated attackers to send specially crafted requests containing ANSI escape sequences (special characters that control how text appears in terminals). When these sequences are logged and displayed in a terminal, they can manipulate the output to hide real security warnings, display fake messages, or mislead administrators reviewing logs.
Vulnerability Details
EPSS: 0.0%
Yes
September 23, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-g7f6-rxc4-qhph
First tracked: September 23, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 85%