spaceship-prompt 4.22.5 及更早版本未对项目清单(project manifest)中的版本字段进行控制字符过滤,便直接将其渲染到 zsh 提示符中。攻击者可以在软件包清单的版本字段中嵌入 ANSI/OSC 转义序列,从而在受害者进入该目录时操纵终端输出、重写窗口标题或伪造显示的文本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| spaceship-prompt | spaceship-prompt | ≤ 4.22.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| spaceship-prompt | spaceship-prompt | 0 ~ 4.22.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet