CVE Explorer
CVE-2026-27113
Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, arbitrary command injection can lead to code execution when a user enters a directory in a Git repository containing a crafted branch name. Exploitation requires the LP_ENABLE_GITSTATUSD config option to be enabled (enabled by default), gitstatusd to be installed and started before Liquid Prompt is loa
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"liquidprompt","vendor":"liquidprompt","versions":[{"status":"affected","version":">= cf3441250bb5d8b45f6f8b389fcdf427a99ac28a, < a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:561970399354878eeb9c17cb2eb7003a71f0fe54abe42057f15bed85a3f81f26 · sha256:4b43b9433c811bd9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:561970399354878eeb9c17cb2eb7003a71f0fe54abe42057f15bed85a3f81f26 · sha256:4b43b9433c811bd9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:561970399354878eeb9c17cb2eb7003a71f0fe54abe42057f15bed85a3f81f26 · sha256:4b43b9433c811bd9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/liquidprompt/liquidprompt/commit/a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c","tags":["x_refsource_MISC"],"url":"https://github.com/liquidprompt/liquidprompt/commit/a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:561970399354878eeb9c17cb2eb7003a71f0fe54abe42057f15bed85a3f81f26 · sha256:4b43b9433c811bd9… · /containers/cna/references/1
{"name":"https://github.com/liquidprompt/liquidprompt/security/advisories/GHSA-q6hm-vf4f-47jf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/liquidprompt/liquidprompt/security/advisories/GHSA-q6hm-vf4f-47jf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:561970399354878eeb9c17cb2eb7003a71f0fe54abe42057f15bed85a3f81f26 · sha256:4b43b9433c811bd9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.