Terminal Escape Sequence Injection in broot by Canop
CVE-2026-72847
2.4LOW
What is CVE-2026-72847?
The broot application by Canop permits terminal escape sequence injection due to unsanitized file and directory names displayed in its interactive tree view. The lack of filtering for control characters allows a local user to create files with escape sequences in their names, which can be displayed unmodified in the terminal of users browsing the directory. This vulnerability enables potential exploitation through commands that can be executed based on the terminal emulator in use, posing a risk to user security as browsing directories with broot is its primary function and typically assumes trusted content.
Affected Version(s)
broot 0 <= 1.58.0
