CVE-2026-66486: CWE-116 Improper Encoding or Escaping of Output in GNU cpio
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed. This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
AI Analysis
Technical Summary
CVE-2026-66486 describes an improper encoding or escaping vulnerability (CWE-116) in GNU cpio's archive member listing feature. When using the 'cpio -it' command to list archive members, the member names are printed directly without quoting or escaping. An attacker can create a malicious cpio archive with member names containing embedded newline characters or ANSI escape sequences, which can cause forged listing entries or terminal control sequence injection when the listing is displayed. This vulnerability was addressed and fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30.
Potential Impact
An attacker who can supply a crafted cpio archive can cause the listing output to be manipulated, potentially forging listing entries or injecting terminal control sequences. This could lead to misleading output or terminal behavior when the archive members are listed. There is no indication of privilege escalation or direct code execution from the provided data.
Mitigation Recommendations
The vulnerability has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30. Users should update to the fixed version of GNU cpio that includes this commit. Since no official patch link or vendor advisory is provided, users should monitor the GNU project for the official release containing this fix. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-66486: CWE-116 Improper Encoding or Escaping of Output in GNU cpio
Description
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed. This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
CVSS v4.0
Score 4.6medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-66486 describes an improper encoding or escaping vulnerability (CWE-116) in GNU cpio's archive member listing feature. When using the 'cpio -it' command to list archive members, the member names are printed directly without quoting or escaping. An attacker can create a malicious cpio archive with member names containing embedded newline characters or ANSI escape sequences, which can cause forged listing entries or terminal control sequence injection when the listing is displayed. This vulnerability was addressed and fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30.
Potential Impact
An attacker who can supply a crafted cpio archive can cause the listing output to be manipulated, potentially forging listing entries or injecting terminal control sequences. This could lead to misleading output or terminal behavior when the archive members are listed. There is no indication of privilege escalation or direct code execution from the provided data.
Mitigation Recommendations
The vulnerability has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30. Users should update to the fixed version of GNU cpio that includes this commit. Since no official patch link or vendor advisory is provided, users should monitor the GNU project for the official release containing this fix. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-07-27T11:32:08.682Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a79aaebbf8831d53985a8dc
Added to database: 08/10/2026, 10:41:47 UTC
Last enriched: 08/10/2026, 11:03:34 UTC
Last updated: 08/10/2026, 16:11:41 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.