Terminal Injection Vulnerability in OpenSSL_Encrypt by OpenSSL
CVE-2026-81696
9.3CRITICAL
What is CVE-2026-81696?
OpenSSL_Encrypt versions prior to 1.4.9 are vulnerable to a terminal injection flaw caused by inadequate sanitization of terminal control characters in file metadata generated by the info command. This vulnerability allows attackers to craft malicious files embedded with escape sequences, which can manipulate terminal output and potentially mislead users by altering displayed verification information, posing significant security risks.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
