This vulnerability has been assigned the CVE identifier CVE-2025-55193
The ID passed to find
or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.
The fixed releases are available at the normal locations.
Thanks to lio346 from Unit 515 of OPSWAT for reporting this vulnerability
{ "github_reviewed_at": "2025-08-13T22:32:18Z", "severity": "MODERATE", "cwe_ids": [ "CWE-150" ], "nvd_published_at": "2025-08-13T23:15:26Z", "github_reviewed": true }