dua-cli fails to filter terminal escape sequences when...
Moderate severity
Unreviewed
Published
Aug 14, 2026
to the GitHub Advisory Database
•
Updated Aug 14, 2026
Description
Published by the National Vulnerability Database
Aug 13, 2026
Published to the GitHub Advisory Database
Aug 14, 2026
Last updated
Aug 14, 2026
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printed, enabling title spoofing, clipboard manipulation, or other escape-sequence attacks.
References