PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35197 Mattiebee CVE debrief

CVE-2026-35197 is a vulnerability in the Dye color library for shell scripts. Prior to version 1.1.1, certain template expressions could lead to arbitrary code execution. The issue was discovered and fixed by the author of Dye and is not known to be exploited. This vulnerability is fixed in version 1.1.1. The vulnerability allows for arbitrary code execution through certain template expressions, categorized as CWE-94, with a CVSS score of 6.6, indicating a medium severity level. Users should be aware of this vulnerability and take steps to upgrade to the latest version.

Vendor
Mattiebee
Product
Dye
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of the Dye color library for shell scripts, especially those using versions prior to 1.1.1, should be aware of this vulnerability and take steps to upgrade to the latest version. This includes developers, system administrators, and security teams who use or manage systems that utilize the Dye library. Additionally, operators and platform administrators should review their systems for potential exposure and take steps to mitigate the vulnerability.

Technical summary

The Dye color library for shell scripts, prior to version 1.1.1, contains a vulnerability that allows for arbitrary code execution through certain template expressions. This issue was discovered and addressed by the library's author. The vulnerability is categorized as CWE-94, and its CVSS score is 6.6, indicating a medium severity level. The library is used for color output in shell scripts, and the vulnerability can be exploited through specially crafted template expressions.

Defensive priority

Medium priority should be given to upgrading to version 1.1.1 or later of the Dye color library to prevent potential arbitrary code execution. This should be done as part of regular vulnerability management and patching processes.

Recommended defensive actions

  • Upgrade to version 1.1.1 or later of the Dye color library
  • Review and update scripts that utilize the Dye library to ensure they are not vulnerable
  • Monitor for any potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-06T20:16:27.380Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. Limited information is available about potential exploits or attacks. The vulnerability was discovered and fixed by the author of Dye, and there are no known exploits. The CVE record and NVD entry provide the most up-to-date information on this vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T20:16:27.380Z and has not been modified since then. The NVD entry is currently Analyzed.