Impact
A malicious or typosquatted package can embed ANSI terminal escape sequences in its metadata, causing the Igniter confirmation panel to overwrite trusted author names and download counts. This deception can persuade developers to approve a dependency that has been tampered with, potentially introducing malicious code into a project. The flaw demonstrates improper neutralization of control sequences (CWE‑150) and is limited to information disclosure and manipulation rather than direct code execution.
Affected Systems
The vulnerability affects Igniter from version 0.8.1 up to, but not including, 0.8.4. Users running any 0.8.x release below 0.8.4 are potentially exposed.
Risk and Exploitability
The CVSS score of 2.3 suggests a low severity, and the EPSS score is not documented, implying limited public exploitation data. It is not listed in CISA’s KEV catalog. Attackers can exploit this by publishing a crafted package to a registry, or creating a typosquatted replacement, which is then installed by a developer relying on the confirmation panel. Given that the attack vector requires control over package metadata, the risk is reasonably low but still actionable.
OpenCVE Enrichment