MEDIUM 4.8 NVD
CVE-2026-73480
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file n
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.
References
- https://github.com/dundee/gdu
- https://github.com/dundee/gdu/commit/fe605ecd9ad0e0f1c7ba84131ddfa1c83c52406f
- https://github.com/dundee/gdu/issues/615
- https://www.vulncheck.com/advisories/gdu-terminal-injection-via-unstripped-escape-sequence
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-08-13 via NVD.
vulnfeed aggregates 11102 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.