Sceawere

Vulnerability Detail

CVE-2026-100867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Spaceship-Prompt Terminal Injection Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
19h ago
Vendor
spaceship-prompt
Product
spaceship-prompt
Attack Type
Improper Neutralization of Escape, Meta, or Control Sequences
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-09-27T13:16:37.810Z",
  "pubdate": "2026-09-27T13:16:37.810Z",
  "executiveSummary": "Spaceship-prompt versions through 4.22.5 are susceptible to a terminal injection vulnerability due to improper sanitization of control characters within project manifest version fields. The vulnerability allows an attacker to inject arbitrary ANSI/OSC (Operating System Command) escape sequences into the Zsh prompt, which are interpreted by the terminal emulator upon rendering.\nThe security impact includes the potential for terminal output manipulation, unauthorized rewriting of window titles, and the spoofing of displayed text within the command-line interface. This vulnerability is triggered when a victim navigates into a directory containing a maliciously crafted manifest file (e.g., package.json).\nThe risk implication is significant as it facilitates social engineering attacks, potentially deceiving users by altering prompt information or hiding command history, leading to unauthorized actions within the terminal environment. Exploitation does not require authentication or elevated privileges, as it relies on the automated rendering of directory-specific metadata by the prompt plugin.\nSuccessful exploitation requires the victim to have a vulnerable version of spaceship-prompt installed and to perform an operation that triggers the prompt's parsing logic within a compromised directory structure.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient input validation of data retrieved from project manifests (such as package.json files) prior to inclusion in the rendered Zsh prompt string. Spaceship-prompt utilizes these manifest files to dynamically display project metadata, such as version numbers, directly in the terminal interface.\nThe application fails to strip or sanitize ANSI escape sequences, specifically those involving Operating System Command (OSC) codes, when processing these fields. Because the terminal emulator interprets these sequences as legitimate instructions rather than plain text, the attacker can hijack the terminal state.\nThe attack flow begins when an attacker places a malicious manifest file in a repository or directory. The manifest's version field is populated with a payload containing ANSI/OSC escape sequences (e.g., \\u001b]0;[Title Changed]\\u0007). When the victim navigates into this directory using a terminal session running the affected version of spaceship-prompt, the shell triggers the prompt rendering function.\nDuring the rendering phase, spaceship-prompt reads the crafted version string and outputs it to stdout as part of the Zsh prompt structure. The terminal emulator receives this output and executes the embedded escape sequences. This behavior permits the attacker to rewrite the window title, inject fake prompt lines, or manipulate the terminal display to trick the user into believing the shell is in a different state or location.\nThe vulnerability is localized to the logic responsible for parsing manifest file metadata. Since the injection occurs during the standard rendering lifecycle of the shell prompt, it operates without specific authentication or authorization requirements. There is no network exposure involved in the exploitation process itself, as the threat is confined to local file system traversal.\nPost-exploitation impact includes persistent visual spoofing, which can be leveraged for sophisticated social engineering, such as creating fake 'sudo' prompts or masking executed commands. By manipulating the OSC sequences, an attacker may also be able to modify the window context to hide malicious activity or exfiltrate state information through terminal-specific escape sequences, significantly undermining the integrity of the command-line environment."
}
CVE-2026-100867: Spaceship-Prompt Terminal Injection Vulnerability (LOW Severity, CVSS: 3.3) | Sceawere