MEDIUM
spaceship-prompt
CVE published 2026-09-27
CVE-2026-100867
CVE-2026-100867 debrief: The spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt, allowing attackers to embed ANSI/OSC escape sequences to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. This issue requires defenders to assess exposure and verify update [truncated]