PatchSiren

raineorshine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM raineorshine CVE published 2026-08-10

CVE-2026-73035

CVE-2026-73035 is a terminal escape sequence injection vulnerability in npm-check-updates through version 23.0.2. The vulnerability allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or --format repo option, unfiltered escape sequences are written directly to the terminal, [truncated]