Impact
procs through 0.14.12 fails to sanitize escape sequences that appear in process command lines before they are rendered in the Command column. A local attacker who can start a process with an attacker‑crafted command arguments containing ANSI or OSC escape codes will have those codes written directly to the terminal of any user running a procs session. The terminal emulator interprets the sequences, allowing the attacker to change cursor position, alter colors, or inject arbitrary characters into terminal state.
Affected Systems
The vulnerable product is dalance procs up to and including version 0.14.12, available for Linux, BSD, and macOS. Users who run any of these environment may be affected, as the escape sequences are written to other column.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity weakness. Exploitation requires the attacker to have local access to the same system and to run a process with a crafted command line; the victim must then have a procs session active on a terminal where the output is displayed. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, but in environments where multiple users share terminals the risk of unintended terminal behavior or potential information disclosure remains realistic.
OpenCVE Enrichment