MEDIUM
o2sh
CVE published 2026-09-27
CVE-2026-100866
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-27T13:16:36.583Z and has not been modified since then. The onefetch tool writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fie [truncated]