CVE-2026-73480

NameCVE-2026-73480
Descriptiongdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gdu (PTS)bullseye4.6.3-1vulnerable
bookworm5.22.0-1vulnerable
trixie5.25.0-1vulnerable
forky, sid5.36.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gdusource(unstable)(unfixed)

Notes

https://github.com/dundee/gdu/issues/615
https://github.com/dundee/gdu/pull/616
Fixed by: https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb

Search for package or bug name: Reporting problems