CWE-150
CWE-150 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-150, highest CVSS first.
- LOW 3.3CVE-2026-100867public PoC
spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manipulate terminal outpu…
- LOW 3.3CVE-2026-100866public PoC
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to ma…
- UNSCOREDCVE-2026-93421public PoC
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/serve…