Impact
In Oh My Posh, versions prior to 29.35.1 emitted attacker‑controlled directory names and Git metadata without stripping control characters such as ESC, BEL, CSI, and OSC. This omission allows an adversary to inject terminal escape sequences during prompt rendering. Injected sequences can overwrite the clipboard, spoof the prompt or screen, manipulate the window title, or generally disrupt terminal operation. The flaw can be leveraged by anyone who can influence the content that appears in the prompt, so local users with access to affected prompt configurations may experience these effects.
Affected Systems
The vulnerability affects the Oh My Posh prompt renderer released by JanDeDobbeleer. All versions older than 29.35.1 are susceptible. Users running older releases of Oh My Posh on any supported operating system should consider the risk.
Risk and Exploitability
The CVSS score is 6.1, indicating medium severity, with score available and the vulnerability not yet listed in CISA’s KEV catalog. The EPSS score is < 1%, indicating a very low probability of exploitation. The likely attack vector is local, requiring an attacker to control or influence prompt segment data presented to the prompt renderer; this could happen through Git hooks, environment configuration, or by supplying malicious file names or directory paths. The impact, while not leading to full system compromise, can affect user experience, arouse suspicion, and potentially compromise clipboard data. Given the lack of confirmed exploitation and moderate CVSS score, the overall risk remains moderate but mitigations are recommended.
OpenCVE Enrichment
Github GHSA