Description
procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.
Published: 2026-09-13
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Terminal Escape Sequence Injection
Action: Patch
AI Analysis

Impact

procs through 0.14.12 fails to sanitize escape sequences that appear in process command lines before they are rendered in the Command column. A local attacker who can start a process with an attacker‑crafted command arguments containing ANSI or OSC escape codes will have those codes written directly to the terminal of any user running a procs session. The terminal emulator interprets the sequences, allowing the attacker to change cursor position, alter colors, or inject arbitrary characters into terminal state.

Affected Systems

The vulnerable product is dalance procs up to and including version 0.14.12, available for Linux, BSD, and macOS. Users who run any of these environment may be affected, as the escape sequences are written to other column.

Risk and Exploitability

The CVSS score of 2.4 indicates a low severity weakness. Exploitation requires the attacker to have local access to the same system and to run a process with a crafted command line; the victim must then have a procs session active on a terminal where the output is displayed. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but in environments where multiple users share terminals the risk of unintended terminal behavior or potential information disclosure remains realistic.

Generated by OpenCVE AI on September 15, 2026 at 16:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the dalance GitHub repository for an update that adds escape‑sequence sanitization and install the latest stable release when it becomes available.
  • Run procs in an isolated terminal or container to prevent other users.
  • If upgrading is not yet possible, modify your process launch scripts or command‑line wrappers to strip ANSI and OSC escape characters from arguments before the process is executed, using tools such as sed or perl.

Generated by OpenCVE AI on September 15, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dalance
Dalance procs
Vendors & Products Dalance
Dalance procs

Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.
Title procs through 0.14.12 Terminal Escape Sequence Injection via Command
Weaknesses CWE-150
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:54.212Z

Reserved: 2026-09-13T10:14:58.418Z

Link: CVE-2026-90773

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:34.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:01.967

Modified: 2026-09-23T17:17:47.480

Link: CVE-2026-90773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-150

    Improper Neutralization of Escape, Meta, or Control Sequences