Junglewise Threat Intelligence

CVE-2026-66486: GNU cpio improper encoding of archive listing output

CVE-2026-66486 · Severity: info · CVSS 0 · Published 2026-08-10

Technologies: Gnu Cpio. Vendors: Gnu.

Executive brief

GNU cpio is a standard archiving utility used to extract and manage backup files. When listing archive contents with the -it flag, the tool can display crafted malicious filenames containing hidden characters or control sequences that trick users or compromise terminal security, potentially causing display manipulation or injection attacks.

Technical details

This vulnerability is a CWE-116 improper encoding/escaping flaw in cpio's archive member listing functionality. When cpio lists archive members via the -it command, member names are printed directly to output without quoting or escaping special characters. An attacker can craft a malicious cpio archive with member names containing embedded newline characters or ANSI escape sequences. These are rendered unescaped during listing, allowing injection of forged listing entries or terminal control sequences that manipulate terminal behavior. The issue is fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30 and affects cpio versions through 2.15.

Affected products

  • GNU cpio through 2.15

Timeline

  • 2026-08-10: disclosed
  • 2026-07-23: patched: Fix released in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30

References

Related threats