CVE-2024-56803
MEDIUMghostty 1.0.0 - Command Injection via Terminal Window Title Escape Sequence
Title source: llmDescription
Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. This attack requires an attacker to send malicious escape sequences followed by convincing the user to physically press the "enter" key. Fixed in Ghostty v1.0.1.
References (2)
Core 2
Core References
Issue Tracking x_refsource_misc
https://github.com/ghostty-org/ghostty/pull/3908
Vendor Advisory x_refsource_confirm
https://github.com/ghostty-org/ghostty/security/advisories/GHSA-5hcq-3j4q-4v6p
Scores
CVSS v4
5.1
EPSS
0.0053
EPSS Percentile
40.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-94
Status
published
Products (1)
ghostty-org/ghostty
< 1.0.1
Published
Dec 31, 2024
Tracked Since
Feb 18, 2026