Terminal Escape Sequence Vulnerability in dua-cli by Byron
CVE-2026-73479
4.8MEDIUM
What is CVE-2026-73479?
The dua-cli version 0.5.0 and earlier contains a flaw that fails to adequately filter terminal escape sequences when displaying marked file paths after exiting the TUI interface. This oversight permits attackers to craft specially formatted file names that exploit the terminal emulator. As a result, malicious actors can manipulate the terminal's title bar, conduct clipboard operations, or execute other escape-sequence based attacks. This vulnerability has implications for users who utilize dua-cli in environments that depend on secure terminal operations.
Affected Version(s)
dua-cli 0 <= 2.41.1
