CVE-2026-73480: Improper Encoding or Escaping of Output in dundee gdu
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.
AI Analysis
Technical Summary
The gdu utility from dundee fails to properly encode or escape terminal escape sequences embedded in directory and file names when displaying paths after the text user interface (TUI) exits. This improper handling enables an attacker who can create or control directory or file names to inject escape sequences that the terminal interprets, potentially leading to terminal title spoofing, clipboard manipulation, or other terminal-dependent effects. The vulnerability has a CVSS 4.8 (medium) score, indicating limited impact and requiring user interaction. There is no vendor advisory or patch information available at this time.
Potential Impact
An attacker able to create or rename files or directories with crafted escape sequences can cause the terminal to interpret these sequences after gdu exits the TUI. This may result in misleading terminal titles, unauthorized clipboard content changes, or other terminal effects that could confuse or mislead the user. The impact is limited to local or low-privilege scenarios where the attacker can influence file or directory names and the user runs gdu and views these names.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid running gdu on untrusted directories or files with potentially malicious names. Consider running gdu in a controlled environment or terminal emulator that limits escape sequence interpretation after TUI exit.
CVE-2026-73480: Improper Encoding or Escaping of Output in dundee gdu
Description
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.
CVSS v4.0
Score 4.8medium
Affected software
dundee
gdu
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The gdu utility from dundee fails to properly encode or escape terminal escape sequences embedded in directory and file names when displaying paths after the text user interface (TUI) exits. This improper handling enables an attacker who can create or control directory or file names to inject escape sequences that the terminal interprets, potentially leading to terminal title spoofing, clipboard manipulation, or other terminal-dependent effects. The vulnerability has a CVSS 4.8 (medium) score, indicating limited impact and requiring user interaction. There is no vendor advisory or patch information available at this time.
Potential Impact
An attacker able to create or rename files or directories with crafted escape sequences can cause the terminal to interpret these sequences after gdu exits the TUI. This may result in misleading terminal titles, unauthorized clipboard content changes, or other terminal effects that could confuse or mislead the user. The impact is limited to local or low-privilege scenarios where the attacker can influence file or directory names and the user runs gdu and views these names.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid running gdu on untrusted directories or files with potentially malicious names. Consider running gdu in a controlled environment or terminal emulator that limits escape sequence interpretation after TUI exit.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-12T18:19:17.024Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7e36abbf8831d539d3060b
Added to database: 08/13/2026, 21:27:07 UTC
Last enriched: 08/13/2026, 21:45:12 UTC
Last updated: 09/26/2026, 18:30:27 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.