Oh My Posh: Arbitrary command execution via template injection in the path segment (CVE-2026-73505)
Oh My Posh versions prior to 29.35.1 contain a vulnerability where the resolved path string is re-rendered as a Go template, evaluating any template expressions in folder names. This allows arbitrary command execution as the current user when the shell prompt renders inside or below a directory with a crafted name. The default configuration is affected, and the issue impacts multiple path styles.
AI Analysis
Technical Summary
Oh My Posh uses the Go text/template engine to render the resolved path string for the shell prompt. The path is composed from raw folder names taken from the filesystem, which are then passed to template.Render with a function map that includes a 'cmd' function capable of executing arbitrary OS commands. If a directory name contains Go template syntax, it is evaluated during prompt rendering, resulting in arbitrary command execution as the user. This affects all path styles and the default configuration. The vulnerability arises from re-parsing the composed path as a template after inserting untrusted folder names. A proof of concept demonstrates command execution by placing template expressions in directory names. The vulnerability is tracked as CVE-2026-73505 with a CVSS 3.1 score of 7.8 (high severity).
Potential Impact
An attacker who can create or control directory names in the filesystem (e.g., via cloned repositories, extracted archives, network shares, or removable drives) can execute arbitrary commands as the victim user when the shell prompt renders inside or below those directories. This can lead to full compromise of the user's environment with high confidentiality, integrity, and availability impact. The vulnerability requires the user to navigate into or below the malicious directory and have Oh My Posh render the prompt, which occurs on the next command after changing directories.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Oh My Posh to version 29.35.1 or later. The suggested fix involves avoiding re-parsing the composed path as a template after inserting untrusted folder names, either by rendering configuration templates individually and concatenating results or by escaping template delimiters in folder names. Until patched, users should avoid navigating into directories with untrusted or attacker-controlled names that may contain template expressions.
Oh My Posh: Arbitrary command execution via template injection in the path segment (CVE-2026-73505)
Description
Oh My Posh versions prior to 29.35.1 contain a vulnerability where the resolved path string is re-rendered as a Go template, evaluating any template expressions in folder names. This allows arbitrary command execution as the current user when the shell prompt renders inside or below a directory with a crafted name. The default configuration is affected, and the issue impacts multiple path styles.
CVSS v3.1
Score 7.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Oh My Posh uses the Go text/template engine to render the resolved path string for the shell prompt. The path is composed from raw folder names taken from the filesystem, which are then passed to template.Render with a function map that includes a 'cmd' function capable of executing arbitrary OS commands. If a directory name contains Go template syntax, it is evaluated during prompt rendering, resulting in arbitrary command execution as the user. This affects all path styles and the default configuration. The vulnerability arises from re-parsing the composed path as a template after inserting untrusted folder names. A proof of concept demonstrates command execution by placing template expressions in directory names. The vulnerability is tracked as CVE-2026-73505 with a CVSS 3.1 score of 7.8 (high severity).
Potential Impact
An attacker who can create or control directory names in the filesystem (e.g., via cloned repositories, extracted archives, network shares, or removable drives) can execute arbitrary commands as the victim user when the shell prompt renders inside or below those directories. This can lead to full compromise of the user's environment with high confidentiality, integrity, and availability impact. The vulnerability requires the user to navigate into or below the malicious directory and have Oh My Posh render the prompt, which occurs on the next command after changing directories.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Oh My Posh to version 29.35.1 or later. The suggested fix involves avoiding re-parsing the composed path as a template after inserting untrusted folder names, either by rendering configuration templates individually and concatenating results or by escaping template delimiters in folder names. Until patched, users should avoid navigating into directories with untrusted or attacker-controlled names that may contain template expressions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6xj8-qv9j-xcjq
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6542199c2644c7f8087e37
Added to database: 07/25/2026, 23:09:13 UTC
Last enriched: 08/13/2026, 19:48:20 UTC
Last updated: 09/02/2026, 07:14:12 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.