Terminal Injection Vulnerability in gdu by Dundee
CVE-2026-73480

4.8MEDIUM

Key Information:

Vendor

Dundee

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73480?

The gdu tool is susceptible to a vulnerability that allows attackers to exploit unstripped terminal escape sequences in directory and file names. When gdu prints these paths after exiting its TUI, the escape sequences can be executed by the terminal, leading to various types of malicious activities such as title spoofing and clipboard manipulation. This creates potential security risks, especially in environments where users may be exposed to crafted names. It is crucial for users to update to the latest version to mitigate these vulnerabilities.

Affected Version(s)

gdu 0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.