Executive brief
dye is a software library used by developers to add colors and formatting to terminal-based shell scripts. A security flaw in how the library processes text templates allows an attacker to execute unauthorized commands on a user's system. This could happen if a script using this library processes a specially crafted filename or piece of text, potentially leading to a full system compromise or data theft.
Technical details
A code injection vulnerability (CWE-94) exists in the dye library's template engine. The vulnerability stems from the use of 'eval' to process template expressions contained within double curly braces. When the library encounters a template, it attempts to execute the contents by passing them to an internal function that uses 'eval' to call the 'tput' utility. An attacker can inject shell metacharacters (e.g., semicolons) into these expressions—for instance, via a maliciously crafted filename processed by a script—to achieve arbitrary command execution. The issue is fixed in version 1.1.1 by removing 'eval' and implementing a safer argument-splitting routine.
Affected products
- mattieb dye 1.1.0
Timeline
- 2026-04-03: advisory: Vendor advisory published by mattieb
- 2026-04-06: disclosed: CVE-2026-35197 published
- 2026-04-06: patched: Fixed in version 1.1.1