PatchSiren

o2sh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM o2sh CVE published 2026-09-27

CVE-2026-100866

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-27T13:16:36.583Z and has not been modified since then. The onefetch tool writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fie [truncated]