CVE Explorer
CVE-2026-50642
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escape sequences (e.g., OSC, CSI), to pass through unsanitized.
An attacker can embed malicious control sequences in filenames, diff metadata, or file content that are rendered directly in the terminal during diff viewing. This can lead to output manipulation, including
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"diff-so-fancy","repo":"https://github.com/so-fancy/diff-so-fancy","vendor":"so-fancy","versions":[{"lessThanOrEqual":"1.4.10","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:78f3357f6880218fe017022d31f6ff3ad4d89398331ee4c1df77f6e9e62c79a6 · sha256:03974afc8017baed… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":4.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:78f3357f6880218fe017022d31f6ff3ad4d89398331ee4c1df77f6e9e62c79a6 · sha256:03974afc8017baed… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:78f3357f6880218fe017022d31f6ff3ad4d89398331ee4c1df77f6e9e62c79a6 · sha256:03974afc8017baed… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2026/07/CVE-2026-41874/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78f3357f6880218fe017022d31f6ff3ad4d89398331ee4c1df77f6e9e62c79a6 · sha256:03974afc8017baed… · /containers/cna/references/0
{"tags":["product"],"url":"https://github.com/so-fancy/diff-so-fancy"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78f3357f6880218fe017022d31f6ff3ad4d89398331ee4c1df77f6e9e62c79a6 · sha256:03974afc8017baed… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.