MEDIUM 4.7 GitHub
CVE-2026-54162
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
## Summary
Ember's interactive TUI renders fields taken from the monitored Caddy server's access logs — most notably the request URI — straight to the operator's terminal without neutralising terminal escape or control sequences (CWE-150). Those log fields are populated from arbitrary, unauthenticated HTTP requests, so any remote client can embed ANSI/OSC/CSI control bytes that the operator's terminal emulator interprets when the log row is displayed. The bytes survive the whole pipeline: Caddy
Affected Products
- go/github.com/alexandre-daubois/ember < 1.4.2
References
- https://github.com/advisories/GHSA-x3g7-qrwc-f6c5
- https://github.com/alexandre-daubois/ember/security/advisories/GHSA-x3g7-qrwc-f6c5
- https://github.com/alexandre-daubois/ember/commit/fcb7160e58dba58d6f9b5033cc312fdedc8c9f6b
- https://github.com/alexandre-daubois/ember/releases/tag/v1.4.2
This medium severity vulnerability with a CVSS score of 4.7 was published on 2026-08-20 via GitHub. Affected: go/github.com/alexandre-daubois/ember < 1.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.