onefetch 2.28.1 及更早版本在将仓库信息字段值写入终端时,未移除控制字符,从而导致终端转义序列注入漏洞。攻击者可以在项目的清单版本和名称字段中嵌入 ANSI/OSC 转义序列,从而在受害者运行 onefetch 时操控终端输出、重写窗口标题、隐藏文本或触发特定终端模拟器的行为。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet