Executive brief
App::Ack (commonly known as ack) is a code-searching tool for programmers. A vulnerability exists where the tool fails to properly clean up special characters in filenames before displaying them in certain modes. This could allow a maliciously named file to manipulate the user's terminal display, potentially hiding information or tricking the user into seeing incorrect output.
Technical details
App::Ack fails to neutralize ANSI escape sequences and terminal control bytes in filenames when using specific output flags, including --show-types, -l/-L, and -c. While version 3.10.0 introduced a _safe_filename helper to sanitize output for -f, -g, and match headings, these specific paths remain vulnerable. An attacker can create a file with a crafted name containing cursor-movement or color escapes. When a user runs ack in an affected mode against a directory containing such a file, the raw escape sequences are emitted to the terminal, allowing for terminal output manipulation or spoofing.
Affected products
- PETDANCE App::Ack (ack) through 3.10.0
Timeline
- 2026-07-08: advisory: CVE-2026-49147 published by NVD