PatchSiren

spaceship-prompt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM spaceship-prompt CVE published 2026-09-27

CVE-2026-100867

CVE-2026-100867 debrief: The spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt, allowing attackers to embed ANSI/OSC escape sequences to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. This issue requires defenders to assess exposure and verify update [truncated]