CVE-2026-75483CWE-150

CVE-2026-75483

Low · published August 18, 2026

CVSS v3.1
3.3
EPSS
0%
Percentile
2.1
In the wild
Unconfirmed
What it is

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.

The record
Technical detail
CVSS v3.1
3.3 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
4.8 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00120 · 2.1th percentile
Weakness
CWE-150 · Improper Neutralization of Escape, Meta, or Control Sequences
Published
2026-08-18T01:16Z
References (5)
EPSS history
Timeline
  • 17 AUG 20:36Z
    powerlevel10k Control Character Injection via package.json Version
    cvelistv5