openSUSE-SU-2026:21675-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21675-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21675-1
Upstream
Related
Published
2026-08-28T21:08:53Z
Modified
2026-08-30T13:00:05Z
Summary
Security update for broot
Details

This update for broot fixes the following issues:

Changes in broot:

  • v1.59.0 (CVE-2026-72847 boo#1275994)

    • new shell_command verb attribute: run a command through a shell (sh -c / cmd /C) so &&, ; and pipes work, without leaving broot - Fix #1145
    • fix invalid official Mac binary (duplicate linked dylib) with new build chain - Fix #1194
    • Sixel graphics support for image preview, auto-detected: works in iterm2, Windows Terminal 1.22+ and Sixel-capable Unix terminals (foot, mlterm, xterm built with Sixel, recent WezTerm). Kitty remains the preferred protocol when available. Note: this requires broot to be compiled with sixel feature (eg cargo install broot --features sixel) - Fix #568
    • High-Res images in Rio terminal (detect it to enable the Kitty image protocol) - Fix #1179
    • fix iTerm2 3.6.10 and later not displaying Hi-Res images, the version being compared as text
    • fix content-exact match line number off-by-one when the match starts at the first byte of a line (broot jumped to the line above)
    • new :no_action internal, doing nothing, which can be used to disable a key - Fix #328
    • fix: detect a duplicate broot server name instead of silently overtaking the running server - Fix #1065
    • fix preview transformers extension matching not working with double extensions such as .tar.gz - Fix #1195
    • strip escape sequences from displayed names to prevent OSC injections - Fix #1188
    • fall back to numeric uid/gid instead of ???? when the user or group name can't be resolved, which is always the case on statically linked musl builds - Fix #1075
    • fix panic on a content regex matching the empty string at the end of a line ending with a control char (eg cr/$/ on a CRLF file)
    • fix Windows paths (containing backslashes) being mangled by the launcher's eval when using :cd and similar; also fixes escaping of paths containing a single quote - Fix #1100
    • fix br failing on Windows/PowerShell when the temp path contains a space (e.g. a space in the Windows username) - Fix #788
    • JPEG XL images are no longer previewed: the decoder had out-of-bounds bugs and the fix needs a more recent rustc (if you need it, tell me and I'll try to make it opt-in)
    • rustc minimal version changed from 1.83 to 1.85, and edition 2024
  • v1.58.0

    • change the way possible verb completions are listed, making it more readable when there are more than what fits the screen
    • fix argument of :select and :show being ignored in a --cmd sequence - Fix 1176
  • v1.57.0

    • help: verb 'keys' and 'description' columns now searchable - Fix #1163
    • fix :print_path / :print_relative_path adding a trailing empty line when printing a multi-item staging area - Fix #1062
    • Skin: attributes (bold, underlined, etc.) of the "selected_line" entry now applied - Fix #1156
    • if no Wezterm version is found, broot now assumes it's recent enough to support kitty protocol for image - Fix #509
  • v1.56.4

    • fix compilation on non unix platforms (1.56.3 isn't available on those systems)
  • v1.56.3

    • fix control characters sometimes remaining in the terminal after broot exit
    • nushell: rename br module to avoid conflict in last nushell version - Fix #1138
    • :open_stay on the staging area opens every staged file through the system opener - Fix #444
  • v1.56.2

    • {file-root-relative} argument - Fix #1142
    • fix :clear_stage (or other operations closing the stage panel) often closing broot - Fix #1143
  • v1.56.1

    • fix a typo in a verb in default conf
  • v1.56.0

    • impacted_panel verb argument, allows the effect of a verb to be on another panel (eg to scroll the preview panel without removing the focus from the tree) - Fix #1119
    • focus_panel_left and focus_panel_right internals - Fix #1115
    • Major Feature: merge staged files to issue a single command: when a verb argument has a space-separated or comma-separated flag, a single external command is run even when the selection is multiple - Fix #465 The default verbs.json file has an example of a zip verb building an archive from all staged files.
  • v1.55.0

  • v1.54.0

    • fix crash on rendering B&W images with Kitty image protocol
    • don't match directories when a composite pattern has a content pattern, even negated (eg /js$/&!c/;: it's clear the user wants to match js files not containing a semicolon)
  • v1.53.0

    • fix some cases of the verb not removed from the input on execution (with a risk of accidental double execution)
    • add the :filesystems (short :fs) verb and state on windows (it was already present on linux and mac).
    • improve the generation of preview pattern from a file tree pattern (i.e. going from /java$/&c/test to /test on opening a matching file in preview). With this change broot avoids filtering the preview when it shouldn't (eg when you searched /java$/|c/test) - See #1097
    • display files whose name isn't valid UTF-8 (they were previously ignored)
    • android executable is back to the official binary archive
  • v1.52.0

    • auto_open_staging_area preference - Fix #1090
    • search content of file target of symlink - Fix #1081
    • fix nushell script (swapped logic for --listen and --listen-auto)
    • return non-zero exit code on error
  • v1.51.0

    • improved image rendering (both speed by using the zune-image library, and quality with bilinear interpolation)
    • fix compilation broken by 1.50.0 on Android
    • --listen-auto listens for commands on a random linux socket - Fix #1064
    • when auto-completing, back-tab cycles in reverse order - Fix #1071
  • v1.50.0

    • big text files now only partially loaded for initial display, remaining being done in background - Fix #1052
    • better support of kitty image protocol over tmux, ssh or unknown terminals, with kitty_graphics_display option and $TMUX_NEST_COUNT env variable - see PR #1034
    • "trash" compilation feature removed: trash related features are built depending on the platform
    • build chain revised. Future official releases should include a Mac binary
    • fix crash on double unstage of last entry in stage panel - fix #1057
    • fallback to transparent background for text preview when the skin specifies nothing
  • v1.49.1

    • watching made much more efficient (some deep changes won't lead to an automatic refresh which only impacts dir size)
    • the name given with --listen is now provided to verb as the {server-name} verb argument
  • v1.49.0

    • :toggle_watch internal, with :watch shortcut, bound by default to alt-w. When watching is active, the tree is refreshed whenever any directory/file, even deep, is changed - Fix #730
    • fallback to a transparent background for images in image preview instead of a specific color - Fix #1040 - Thanks @letmeiiiin
    • fix --server socket written at a non writable location on Android/termux - Fix #1045
  • v1.48.0

    • Support for the 'Cmd' modifier in key shortcuts (the key is called 'Command', 'Super', 'Apple', 'Windows', depending on systems and users)
    • "filesystem" features have been made available for Mac:
      • the :fs screen, listing filesystems
      • filesystem free space & total space displayed when size computations are requested
      • device id displayed with :toggle_device_id (shortcut: "dev")
    • Fix .config/git/ignore not being loaded on Mac - Fix #1032 - Thanks @9999years
  • v1.47.0

    • text files with control chars were previously previewed as binary. They're now displayed as text with some '�' when needed - Fix #977
    • files with ANSI escape codes (such as the one you would obtain with dysk --color yes > ansi.txt can now be previewed with :preview_tty - Fix #1019
    • first line of the tree is cropped (right aligned) when it doesn't fit
  • v1.46.5

    • fix :focus some/path called in a command sequence always opening new panel - Fix #1014
  • v1.46.4

    • support for keys F13 to F24 (if your system supports it)
    • fix :focus with argument given in configuration going up one level when root is selected - Fix #1009
    • fix --max-depth ignored when in default_flags - Fix #1013
  • v1.46.3

    • fix broot waiting for events on internals like :quit - Fix #1006
  • v1.46.2

    • fix broken nushell script (--max-depth again)
  • v1.46.1

    • fix nushell script broken by new --max-depth argument
  • v1.46.0

    • :set_max_depth and :unset_max_depth
    • clear cache when files are deleted in staging area
    • recompute preview transform when source file changed since last preview
  • v1.45.1

    • Fix compilation failing without --locked
  • v1.45.0

    • Fix total search impossible to redo after refresh
    • With refresh_after: false, a verb configuration can request that the tree isn't refreshed after its execution
  • v1.44.7

    • fix bad regex match position
    • update resvg dependency to 0.44
    • on --server, remove the existing socket if it already exists
  • v1.44.6

    • fix .ignore files ignored when not in a git repository
    • update git2 dependency to 0.20
  • v1.44.5

    • no real change (just reverting a crate name to ease some packaging)
  • v1.44.4

    • fix panic in preview on syntax coloring (when a sublime syntax isn't compatible with the regex engine)
  • v1.44.3

    • removed default bindings on left and right keys. You may add them back by adding this to your verbs.hjson: { key: "left", internal: "back" } { key: "right", internal: "open_stay" }
    • rustc minimal version changed from 1.76 to 1.79, which allows better performing image rendering
    • remove dependency to onig, to allow compatibility with gcc 15
  • v1.44.2

    • temp files created for kitty now erased on quitting or when too many of them have been written
    • no longer panics when launched with BROOT_LOG=debug but the broot.log file can't be created
    • fix user and group names displayed as "????" when coming from openldap
  • v1.44.1

    • fix wrong position of IMEs (input method editors) popup - See #948
    • improve querying the terminal for capabilities (prevent some escape chars from leaking)
  • v1.44.0

    • :focus_staging_area_no_open internal, focus the staging area if it's already open, does nothing in other case
    • fix some composite patterns with several operators and no parenthesis
  • v1.43.0

    • 'Size' and 'Deletion date' columns in trash screen. This screen now supports the :toggle_date, :toggle_size, :sort_by_date, and :sort_by_size internals.
    • new :show internal make the provided path visible and selected, adding lines to the tree if necessary, does nothing if the provided path is not a descendant of the current tree root (this part may change depending on feedback)
  • v1.42.0

    • support of .ignore files with the same syntax than .gitignore. They have priority over .gitignore so that a personal .ignore file can override a shared .gitignore - See https://dystroy.org/broot/tree_view/#hidden-ignored-files
    • :toggle_ignore internal, identical to :toggle_git_ignore, but with a clearer name so should be preferred
    • the panels verb filter now works in most contexts (it was previously only checked on key events)
    • many dependencies updated
  • v1.41.1

    • allow compilation with rustc 1.76
  • v1.41.0

    • Major Feature: :search_again
      • ctrl-s now triggers :search_again which either
      • brings back the last used search pattern, when no filtering pattern is active
      • does a "total search" if a filtering pattern is active and the search wasn't complete
    • Major Feature: internals changing panel widths
      • set_panel_width, taking as parameter the index of the panel and the desired width
      • move_panel_divider, taking as parameter the index of the divider and the desired change
      • ctrl-< is bound by default to :move_panel_divider 0 -1
      • ctrl-> is bound by default to :move_panel_divider 0 1
      • See http://dystroy.org/broot/panels/#resize-panels
    • Minor Changes:
      • when git file infos are shown, and git ignored files aren't hidden, those files are flagged with a 'I'
      • Remove .bak extension from content search exclusion list
      • Update nerdfont and vscode icons
      • {initial-root} verb argument
  • v1.40.0

    • Major Feature: preview transformers You can now define preview transformers to be applied before preview. They allow for example previewing PDF or Office files, or beautifying JSON files. Edit the preview_transformers array in your conf.hjson file. See https://dystroy.org/broot/conf_file/#preview
    • fix search on root
    • fix some verb cycling problems
  • v1.39.2

    • fix UNC paths being displayed on Windows (regression at 1.39.1)
  • v1.39.1

    • fix high-resolution (kitty protocole) image broken in release mode
    • canonicalize paths when focusing them (mostly useful when following links)
    • a few minor internal optimizations
References

Affected packages

openSUSE:Leap 16.0 / broot

Package

Name
broot
Purl
pkg:rpm/opensuse/broot&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.59.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "broot":  "1.59.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21675-1.json"