Terminal Injection Vulnerability in gdu by Dundee
CVE-2026-73480
4.8MEDIUM
What is CVE-2026-73480?
The gdu tool is susceptible to a vulnerability that allows attackers to exploit unstripped terminal escape sequences in directory and file names. When gdu prints these paths after exiting its TUI, the escape sequences can be executed by the terminal, leading to various types of malicious activities such as title spoofing and clipboard manipulation. This creates potential security risks, especially in environments where users may be exposed to crafted names. It is crucial for users to update to the latest version to mitigate these vulnerabilities.
Affected Version(s)
gdu 0
