MEDIUM
raineorshine
CVE published 2026-08-10
CVE-2026-73035
CVE-2026-73035 is a terminal escape sequence injection vulnerability in npm-check-updates through version 23.0.2. The vulnerability allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or --format repo option, unfiltered escape sequences are written directly to the terminal, [truncated]