Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82710— Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata

Quick assessment

Affected
ash-project usage_rules
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

中 存在“转义序列、元字符或控制序列的不当中和”漏洞,允许恶意的包发布者将终端控制序列注入到 的输出中。 通过 搜索 Hex 文档(该服务索引了所有已发布包的文档),并将匹配结果(标题、包名、类型、文档引用及高亮片段)打印到终端。 中的格式化器直接原样插值了这些由发布者控制的字段,未对终端控制字符进行任何中和处理;其唯一应用的转换操作是添加转义序列,而非移除控制字符。恶意包可以在其索引的文档中嵌入 ANSI 终端转义序列(如光标移动、行擦除、回车符、OSC 52 剪贴板写入等),因此,当开发者运行搜索并显示这些文档

CVSS 2.3 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82710

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which indexes the documentation of every published package, and prints the matching results (title, package, type, doc reference, and highlighted snippets) to the terminal. The formatter in Mix.Tasks.UsageRules.SearchDocs interpolated those publisher-controlled fields verbatim, neutralizing no terminal control characters; the only transform it applied adds escape sequences rather than removing them. A malicious package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns, OSC 52 clipboard writes) in its indexed documentation, so when a developer runs a search that surfaces those docs the sequences reach the terminal unchanged — forging the displayed hexdocs URL or a suggested command, hiding text, or writing to the clipboard. No authentication or privileged position is required; only publishing a package. This issue affects usage_rules: from 0.1.18 before 1.2.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
转义、元或控制序列转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project usage_rules 0.1.18 ~ 1.2.8 cpe:2.3:a:ash-project:usage_rules:*:*:*:*:*:*:*:*
ash-project usage_rules 2da7a99536041d63ec1f391d019565789a59595f ~ 3b8ebb4117d3272bbd436e6c2432113ba6685dbb cpe:2.3:a:ash-project:usage_rules:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-82710

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82710

登录查看更多情报信息。

Patches & Fixes for CVE-2026-82710 (1)

Vendor Advisories for CVE-2026-82710 (1)

News Coverage for CVE-2026-82710 (1)

Vendor Pages for CVE-2026-82710 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82710

No comments yet


Leave a comment