CVE-2026-26982

Source
https://cve.org/CVERecord?id=CVE-2026-26982
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26982.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26982
Aliases
  • GHSA-4jxv-xgrp-5m3r
Downstream
Related
Published
2026-03-09T21:14:27Z
Modified
2026-08-12T03:51:08Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Ghostty affected by arbitrary command execution via control characters in paste and drag-and-drop operations
Details

Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell environments. This attack requires an attacker to convince the user to copy and paste or drag and drop malicious text. The attack requires user interaction to be triggered, but the dangerous characters are invisible in most GUI environments so it isn't trivially detected, especially if the string contents are complex. Fixed in Ghostty v1.3.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26982.json"
}
References

Affected packages

Git / github.com/ghostty-org/ghostty

Affected ranges

Type
GIT
Repo
https://github.com/ghostty-org/ghostty
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:ghostty:ghostty:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26982.json"