Terminal Escape Sequence Injection in broot by Canop
CVE-2026-72847

2.4LOW

Key Information:

Vendor

Canop

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-72847?

The broot application by Canop permits terminal escape sequence injection due to unsanitized file and directory names displayed in its interactive tree view. The lack of filtering for control characters allows a local user to create files with escape sequences in their names, which can be displayed unmodified in the terminal of users browsing the directory. This vulnerability enables potential exploitation through commands that can be executed based on the terminal emulator in use, posing a risk to user security as browsing directories with broot is its primary function and typically assumes trusted content.

Affected Version(s)

broot 0 <= 1.58.0

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

carfeii
.