CVE-2026-100866
Description
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/o2sh/onefetch
- https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/utils/info_field.rs#L43-L55
- https://github.com/o2sh/onefetch/blob/9beb80329cf2e5bd784270f668139f0bafb48e2b/src/info/version.rs#L33-L35
- https://github.com/o2sh/onefetch/issues/1828
- https://www.vulncheck.com/advisories/onefetch-through-2.28.1-terminal-escape-sequence-injection
CWEs
CWE-150
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.