MEDIUM 4.8 NVD

CVE-2026-75483

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escap

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.

References

Published: 2026-08-17 · Source: NVD · Feed updated: 2026-08-18
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.