Showing 1 vulnerability on this page for flawfinder

Signals CISA KEV Ransomware Nuclei
PyPI vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Flawfinder output manipulation via untrusted filenames and source text

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape sequences can end up being included in flawfinder's standard terminal output, with many effects. Untrusted fields (such as filenames, categories, or code context text) were not properly sa

CWE-74Aug 11, 2026
CVSS8.7v4.0EPSS0.326%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX