CVE-2026-100866: o2sh Onefetch
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.
Affected products
- o2sh Onefetch: up to and including 2.28.1
Published 2026-09-27. Last modified 2026-09-30.