Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82584— Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata

Quick assessment

Affected
ash-project igniter
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ash-project 的 igniter 中存在“转义、元字符或控制序列未正确中和”的漏洞,恶意包发布者借此伪造 的确认提示。 在添加包之前会打印一个确认面板(一种防止拼写仿冒的安全机制),列出该包的十六进制元数据。Igniter.Project.Deps 中的面板构建器在将发布者可控的字段( 、所有者用户名、依赖项名称、版本号)写入终端时,仅去除了换行符。恶意或拼写仿冒的包可以在其元数据中嵌入 ANSI 终端转义序列(光标移动、清行、回车等),从而覆盖面板内容:伪造可信的作者名和下载量,同时隐藏真实信息。依赖该

CVSS 2.3 · Low

Possible ATT&CK Techniques 1 AI

T1565 · Data Manipulation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82584

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation panel (an anti-typosquatting safeguard) listing a package's hex metadata before adding it. The panel builder in Igniter.Project.Deps wrote publisher-controlled fields (meta.description, owner usernames, requirement names, version) to the terminal with only newlines stripped. A malicious or typosquatted package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns) in its metadata to overwrite the panel, forging trusted author names and download counts while concealing the real ones, so a developer relying on the panel to vet the package is deceived into approving a malicious dependency. This issue affects igniter: from 0.8.1 before 0.8.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
转义、元或控制序列转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project igniter 0.8.1 ~ 0.8.4 cpe:2.3:a:ash-project:igniter:*:*:*:*:*:*:*:*
ash-project igniter d26d9b3a8348661813617606076315075d32663b ~ d492b1aa33f8fb0dacc0afa41b703fb922d42816 cpe:2.3:a:ash-project:igniter:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-82584

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82584

登录查看更多情报信息。

Patches & Fixes for CVE-2026-82584 (1)

Vendor Advisories for CVE-2026-82584 (1)

Vendor Pages for CVE-2026-82584 (1)

Other References for CVE-2026-82584 (1)

Same Patch Batch · ash-project · 2026-09-07 · 9 CVEs total

CVE-2026-82753 8.2 HIGH Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and c
CVE-2026-82586 8.2 HIGH AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private at
CVE-2026-82755 6.3 MEDIUM ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheab
CVE-2026-82758 6.3 MEDIUM ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gat
CVE-2026-82754 6.3 MEDIUM ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypas
CVE-2026-82757 6.3 MEDIUM ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addre
CVE-2026-82756 6.3 MEDIUM ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenti
CVE-2026-81638 2.1 LOW Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry

IV. Related Vulnerabilities

V. Comments for CVE-2026-82584

No comments yet


Leave a comment