Improper Neutralization Vulnerability in Ash-Project Igniter
CVE-2026-82584

2.3LOW

Key Information:

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-82584?

A vulnerability in Ash-Project Igniter permits the creation of malicious packages that can manipulate the mix igniter.install confirmation prompt. This occurs through improper handling of metadata, allowing attackers to embed ANSI escape sequences to disguise their identity and mislead developers into installing harmful dependencies. The flaw impacts versions from 0.8.1 up to, but not including, 0.8.4, potentially exposing users to risks associated with unverified package installations.

Affected Version(s)

igniter 0.8.1 < 0.8.4

igniter d26d9b3a8348661813617606076315075d32663b

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.