Description
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes.

When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper that sanitises the filenames printed by -f, -g, the colored match heading, and per-match lines, but the --show-types, -l/-L, and -c paths still emit the raw filename.

A file whose name embeds cursor-movement or color escapes can overwrite or recolor earlier terminal output, or be passed unchanged to a downstream consumer.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

App::Ack versions up to 3.10.0 print filenames containing terminal control characters, such as ANSI escape sequences, directly to the terminal or to downstream consumers without sanitisation in several output modes. This allows an attacker to craft a file whose name embeds cursor‑movement, colour, or screen‑clear codes; when ack processes such a file the terminal interprets the codes, enabling the attacker to overwrite or recolour earlier output or otherwise manipulate the terminal session. The flaw is a classic example of improper sanitisation of user‑controlled content (CWE‑150).

Affected Systems

The impacted product is PETDANCE: App::Ack. All releases from the earliest version through 3.10.0 are vulnerable. The 3.10.0 release introduced a _safe_filename helper that sanitises the filenames printed by –f, –g, the coloured match heading, and per‑match lines, but it does not affect the –show‑types, –l, –L, or –c options, which continue to emit raw paths.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of < 1% signals a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue, so no public exploits are known. Based on the description, attack vector is local; any user who can execute ack against a directory containing specially named files can trigger the injection, leading to terminal tampering or corruption of scripts that process ack's output.

Generated by OpenCVE AI on July 29, 2026 at 14:04 UTC.

Remediation

Vendor Solution

Upgrade to a future ack release.


Vendor Workaround

Pipe ack output through a filter that strips terminal control characters when running ack over untrusted filenames.


OpenCVE Recommended Actions

  • Upgrade to a future ack release that sanitises all output modes.
  • Pipe ack output through a filter that strips ANSI escape codes, for instance: `ack0-9;]*[mKD]//g`.
  • Avoid running ack on directories that contain filenames with embedded terminal control characters.
  • Sanitise ack’s output before forwarding it to downstream consumers or scripts that parse its output.

Generated by OpenCVE AI on July 29, 2026 at 14:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Petdance
Petdance app::ack
Vendors & Products Petdance
Petdance app::ack

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper that sanitises the filenames printed by -f, -g, the colored match heading, and per-match lines, but the --show-types, -l/-L, and -c paths still emit the raw filename. A file whose name embeds cursor-movement or color escapes can overwrite or recolor earlier terminal output, or be passed unchanged to a downstream consumer.
Title App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
Weaknesses CWE-150
References

Subscriptions

Petdance App::ack
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-08T17:31:34.336Z

Reserved: 2026-05-27T17:50:04.538Z

Link: CVE-2026-49147

cve-icon Vulnrichment

Updated: 2026-07-08T17:31:34.336Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:15:03Z

Weaknesses
  • CWE-150

    Improper Neutralization of Escape, Meta, or Control Sequences