Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100866— onefetch through 2.28.1 Terminal Escape Sequence Injection

Quick assessment

Affected
o2sh onefetch
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

onefetch 2.28.1 及更早版本在将仓库信息字段值写入终端时,未移除控制字符,从而导致终端转义序列注入漏洞。攻击者可以在项目的清单版本和名称字段中嵌入 ANSI/OSC 转义序列,从而在受害者运行 onefetch 时操控终端输出、重写窗口标题、隐藏文本或触发特定终端模拟器的行为。

CVSS 3.3 · Low EPSS 0.13% · P2

Possible ATT&CK Techniques 1 AI

T1608 · Stage Capabilities

Affected Version Matrix 1

VendorProduct Version RangeStatus
o2sh onefetch ≤ 2.28.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100866

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
onefetch through 2.28.1 Terminal Escape Sequence Injection
Source: CVE Program / CVE List V5
Vulnerability Description
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
转义、元或控制序列转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
o2sh onefetch 0 ~ 2.28.1 -

II. Public POCs for CVE-2026-100866

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100866

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-100866 (2)

Vendor Advisories for CVE-2026-100866 (1)

Other References for CVE-2026-100866 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100866

No comments yet


Leave a comment