PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72847 Canop CVE debrief

The broot vulnerability (CVE-2026-72847) allows local users to inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. This issue arises because broot renders file and directory names in its interactive tree view without proper control-character filtering. Users with untrusted local access can exploit this by creating files or directories with malicious names, injecting terminal escape sequences that can be executed when another user browses the directory using broot. The impact of such an injection depends on the terminal emulator in use. To mitigate this vulnerability, users should restrict untrusted user file system modifications and implement terminal emulator hardening. Additionally, compensating controls such as file system access controls and monitoring for suspicious file system activity should be considered. It's crucial for security teams to prioritize patching or mitigating this vulnerability to prevent potential unauthorized actions in the terminal. Asset inventory and change management processes should be updated to account for this vulnerability, and monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts.

Vendor
Canop
Product
broot
CVSS
LOW 2.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-20
Original CVE updated
2026-08-21
Advisory published
2026-08-20
Advisory updated
2026-08-21

Who should care

Users of broot, especially those with untrusted local users, should be aware of this vulnerability and take steps to mitigate it. This includes restricting untrusted user file system modifications and implementing terminal emulator hardening. Additionally, users should review their system configurations and consider compensating controls such as file system access controls and monitoring for suspicious file system activity. Security teams should prioritize patching or mitigating this vulnerability to prevent potential unauthorized actions in the terminal. Vulnerability management and security teams should also review the affected product scope and assess the potential operational impact on their organization. Asset inventory and change management processes should be updated to account for this vulnerability. Monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts. Rollback and change window processes should be updated to ensure rapid remediation of exposed systems. Source tracking and incident response plans should be updated to account for this vulnerability. Compensating controls such as file system access controls and monitoring should be implemented to reduce the risk of exploitation. The vulnerability management team should track exceptions and retest remediated assets to ensure the vulnerability is properly mitigated. The security team should also review relevant monitoring, detection, and logs for exposed assets that need extra review. The incident response plan should be updated to account for potential exploitation of this vulnerability. The security team should also consider implementing additional security controls such as restricting untrusted user file system modifications and implementing terminal emulator hardening. The vulnerability management team should also review the affected product scope and assess the potential operational impact on their organization. The security team should prioritize patching or mitigating this vulnerability to prevent potential unauthorized actions in the terminal. The incident response plan should be updated to account for potential exploitation of this vuln

Technical summary

broot renders file and directory names in its interactive tree view without control-character filtering. This allows local users to inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. The vulnerability is particularly concerning for users with untrusted local users, as they can create files or directories with malicious names that can be used to inject terminal escape sequences.

Defensive priority

Local users with file creation capabilities can inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. Defensive priority should be placed on restricting untrusted user file system modifications and implementing terminal emulator hardening.

Recommended defensive actions

  • Restrict untrusted user file system modifications
  • Implement terminal emulator hardening
  • Monitor for suspicious file system activity
  • Consider compensating controls like file system access controls
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence is based on limited source detail from Vulncheck and NVD. Primary records indicate broot's tree view renders file and directory names without control-character filtering, allowing potential escape sequence injection. Further verification is needed to assess full impact and scope. The vulnerability allows local users to inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. Users should verify their systems for untrusted local users and consider compensating controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T18:16:45.540Z and has not been modified since then.