CVE-2026-73480 MEDIUM

CVE-2026-73480: gdu Terminal Injection via Unstripped Escape Sequences

Vendor Dundee
Product gdu
Weakness CWE-116
Published August 13, 2026
Last update August 14, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 14, 2026 Record updated