PatchSiren cyber security CVE debrief
CVE-2026-100867 spaceship-prompt CVE debrief
CVE-2026-100867 debrief: The spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt, allowing attackers to embed ANSI/OSC escape sequences to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. This issue requires defenders to assess exposure and verify updates to prevent potential terminal output manipulation and other security risks associated with the vulnerability.
- Vendor
- spaceship-prompt
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
Defenders responsible for maintaining and securing systems using spaceship-prompt should assess exposure and verify updates to prevent potential terminal output manipulation and other security risks associated with the vulnerability. They should review project manifest version fields for suspicious activity and monitor terminal output for signs of exploitation. Additionally, defenders should prioritize verifying and updating spaceship-prompt to address the
Why it matters
Defenders should care about CVE-2026-100867 as it allows attackers to manipulate terminal output, potentially leading to spoofed displayed text or rewritten window titles, and requires verification and updates to spaceship-prompt.
- Potential terminal output manipulation
- Possible window title rewriting
- Spoofed displayed text when victims enter the directory
Technical summary
The spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. This allows attackers to embed ANSI/OSC escape sequences to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. Defenders should prioritize verifying and updating spaceship-prompt to address potential terminal output manipulation and review project manifest version fields for suspicious activity. The vulnerability requires verification and updates to spaceship-prompt to prevent potential security risks.
Defensive priority
Defenders should prioritize verifying and updating spaceship-prompt to address potential terminal output manipulation.
Recommended defensive actions
- Verify and update spaceship-prompt to the latest version
- Review and sanitize project manifest version fields
- Monitor terminal output for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source references indicate that spaceship-prompt through 4.22.5 is vulnerable to terminal output manipulation via ANSI/OSC escape sequences in package manifest version fields. Defenders should verify and update spaceship-prompt to address potential terminal output manipulation and review project manifest version fields for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100867 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100867
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100867 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100867
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/spaceship-prompt/spaceship-prompt
-
Source reference
Unverified legacy reference
URL: https://github.com/spaceship-prompt/spaceship-prompt/blob/fd0d6653a134fe28f498eae1784fbb46d27f20f3/lib/section.zsh
-
Source reference
Unverified legacy reference
URL: https://github.com/spaceship-prompt/spaceship-prompt/blob/fd0d6653a134fe28f498eae1784fbb46d27f20f3/sections/package.zsh
-
Source reference
Unverified legacy reference
URL: https://github.com/spaceship-prompt/spaceship-prompt/issues/1567
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/spaceship-prompt-through-4.22.5-terminal-escape-sequence-injection
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.