CWE-150

CWE-150 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-150, highest CVSS first.

  1. LOW 3.3CVE-2026-100867public PoC

    spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manipulate terminal outpu…

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.3CVE-2026-100866public PoC

    onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to ma…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-93421public PoC

    Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/serve…

    AI risk analysis on Exploit-DB.ai →