Terminal Escape Sequence Injection in procs by Dalance
CVE-2026-90773

2.4LOW

Key Information:

Vendor

Dalance

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90773?

A vulnerability exists in procs release 0.14.12 that allows local attackers to exploit unescaped ANSI or OSC escape sequences within process command lines. This oversight results in malicious command line arguments being displayed unmodified in terminal emulators for other users, potentially allowing local users to manipulate what other users see or execute. The vulnerability arises from the lack of sanitization of these sequences before they are rendered, presenting significant risks for users interacting with potentially compromised command outputs.

Affected Version(s)

procs 0 <= 0.14.12

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.