PatchSiren

Canop CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Canop CVE published 2026-08-20

CVE-2026-72847

The broot vulnerability (CVE-2026-72847) allows local users to inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. This issue arises because broot renders file and directory names in its interactive tree view without proper control-character filtering. Users with untrusted local access can exploit this by creating files or directories [truncated]