Terminal Escape Sequence Injection in procs by Dalance
CVE-2026-90773
2.4LOW
What is CVE-2026-90773?
A vulnerability exists in procs release 0.14.12 that allows local attackers to exploit unescaped ANSI or OSC escape sequences within process command lines. This oversight results in malicious command line arguments being displayed unmodified in terminal emulators for other users, potentially allowing local users to manipulate what other users see or execute. The vulnerability arises from the lack of sanitization of these sequences before they are rendered, presenting significant risks for users interacting with potentially compromised command outputs.
Affected Version(s)
procs 0 <= 0.14.12
