CVE-2026-75483

Source
https://cve.org/CVERecord?id=CVE-2026-75483
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75483.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75483
Published
2026-08-17T20:36:08Z
Modified
2026-08-22T03:31:11Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
powerlevel10k Control Character Injection via package.json Version
Details

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-150"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75483.json"
}
References

Affected packages

Git / github.com/romkatv/powerlevel10k

Affected ranges

Type
GIT
Repo
https://github.com/romkatv/powerlevel10k
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.20.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0
v1.1
v1.10.0
v1.10.1
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.15.0
v1.16.0
v1.16.1
v1.17.0
v1.18.0
v1.19.0
v1.2.0
v1.20.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.9.0
v1.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75483.json"