CVE-2024-56803

MEDIUM

ghostty 1.0.0 - Command Injection via Terminal Window Title Escape Sequence

Title source: llm
STIX 2.1

Description

Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. This attack requires an attacker to send malicious escape sequences followed by convincing the user to physically press the "enter" key. Fixed in Ghostty v1.0.1.

References (2)

Core 2
Core References
Issue Tracking x_refsource_misc
https://github.com/ghostty-org/ghostty/pull/3908

Scores

CVSS v4 5.1
EPSS 0.0053
EPSS Percentile 40.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
ghostty-org/ghostty < 1.0.1
Published Dec 31, 2024
Tracked Since Feb 18, 2026