Sceawere
Vulnerability Detail
CVE-2026-100866UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Onefetch Terminal Escape Sequence Injection
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.3
- Creation Date
- 19h ago
- Vendor
- o2sh
- Product
- onefetch
- Attack Type
- Improper Neutralization of Escape, Meta, or Control Sequences
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.3",
"pubDate": "2026-09-27T13:16:36.583Z",
"pubdate": "2026-09-27T13:16:36.583Z",
"executiveSummary": "Onefetch versions up to and including 2.28.1 are vulnerable to terminal escape sequence injection. This vulnerability stems from the application's failure to sanitize repository metadata, such as version and name fields, before rendering them to the standard output.\nBy embedding malicious ANSI or OSC (Operating System Command) escape sequences within these fields in a project's manifest, an attacker can manipulate the victim's terminal environment. The vulnerability allows for unauthorized terminal state changes, including rewriting the window title, masking or hiding command output, and potentially triggering emulator-specific behaviors that could lead to further exploitation.\nThe vulnerability is triggered locally when a user executes onefetch within a repository containing crafted metadata. Since the tool is designed to parse and display information from git repositories, the attack vector is effectively a 'malicious repository' scenario. It does not require special privileges beyond the ability to run the tool against the compromised directory. The risk implications include potential social engineering, deception of the user through output manipulation, and the exploitation of vulnerabilities within specific terminal emulators.",
"technicalDetails": "The root cause of this vulnerability is improper input validation and output encoding in onefetch. The application retrieves repository information—specifically project names and version strings—from configuration files or repository metadata and writes these raw strings directly to the terminal's standard output stream.\nTerminal emulators interpret specific byte sequences, known as ANSI escape codes or Operating System Commands (OSC), as control instructions rather than literal text. When onefetch fails to sanitize or escape these sequences, it facilitates an injection attack where an attacker controls the terminal's display state via the repository content.\nThe attack flow proceeds as follows: 1. An attacker modifies a project manifest or repository configuration file (such as package.json or similar files parsed by onefetch) to include malicious payloads within the 'name' or 'version' fields. 2. A victim clones the repository or navigates to the directory containing the malicious metadata. 3. The victim executes onefetch. 4. Onefetch reads the malicious fields and prints them to the terminal. 5. The terminal emulator receives the injected escape sequences and executes them as commands.\nExploitation allows for several impact scenarios: OSC sequences can be used to set the terminal window title, which might be used to deceive a user into believing they are in a different environment. More severe payloads could include hiding subsequent output, clearing lines, or manipulating input buffers to facilitate command injection if the user is prompted to type. Furthermore, certain terminal emulators support proprietary escape codes that can trigger file transfers, system notifications, or deep integration features, increasing the potential attack surface.\nThis vulnerability affects onefetch versions up to and including 2.28.1. It is a local attack that requires no authentication, provided the user has execute permissions on the repository directory. The impact is primarily contained within the context of the user's terminal session, but the consequences scale based on the capabilities of the specific terminal emulator being utilized by the victim."
}