CVE-2026-73480

NameCVE-2026-73480
Descriptiongdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144461

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gdu (PTS)bookworm5.22.0-1vulnerable
trixie5.25.0-1vulnerable
forky, sid5.36.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gdusource(unstable)(unfixed)unimportant1144461

Notes

https://github.com/dundee/gdu/issues/615
https://github.com/dundee/gdu/pull/616
Fixed by: https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
Not considered a security issue, needs to be correctly handled in the terminal emulators

Search for package or bug name: Reporting problems