PatchSiren

Bash-it CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Bash-it CVE published 2026-08-11

CVE-2026-73036

A terminal escape sequence injection vulnerability exists in Bash-it 3.2.0's barbuk theme, specifically in the Python virtualenv prompt segment. This vulnerability allows local attackers to inject arbitrary terminal control sequences by manipulating the requires-python field of a pyproject.toml file. When a user navigates into a directory containing a maliciously crafted pyproject.toml, the unfiltered fie [truncated]