Improper Neutralization Vulnerability in ash-project's usage_rules Affects Hex Documentation
CVE-2026-82710
2.3LOW
What is CVE-2026-82710?
The vulnerability in ash-project's usage_rules allows malicious package publishers to inject terminal control sequences through indexed documentation on search.hexdocs.pm. When developers use the mix usage_rules.search_docs command, these sequences can manipulate terminal output, potentially leading to forged URLs, hidden text, or unauthorized clipboard writes. No special authentication is necessary for attackers, making this a significant risk for users who rely on the affected versions of usage_rules.
Affected Version(s)
usage_rules 0.1.18 < 1.2.8
usage_rules 2da7a99536041d63ec1f391d019565789a59595f < 3b8ebb4117d3272bbd436e6c2432113ba6685dbb
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
