LOW
Canop
CVE published 2026-08-20
CVE-2026-72847
The broot vulnerability (CVE-2026-72847) allows local users to inject terminal escape sequences via file or directory names, potentially leading to unauthorized actions in the terminal. This issue arises because broot renders file and directory names in its interactive tree view without proper control-character filtering. Users with untrusted local access can exploit this by creating files or directories [truncated]