HIGH
david-a-wheeler
CVE published 2026-08-11
CVE-2026-48813
Flawfinder, a static analysis tool for C/C++ source code, has an improper input neutralization issue leading to output manipulation in versions prior to 2.0.20. This vulnerability allows for Terminal/ANSI Escape Sequence Injection and XML Injection when a malicious file with ANSI escape sequences in its name is processed. The issue impacts users who evaluate intentionally malicious filenames or file conte [truncated]