Junglewise Threat Intelligence

CVE-2026-73480: gdu terminal escape sequence injection in path output

CVE-2026-73480 · Severity: medium · CVSS 5 · Published 2026-08-13

Executive brief

gdu is a fast disk usage analyzer with a terminal interface. When exiting the interactive UI, gdu prints directory and file paths without stripping terminal escape sequences, allowing an attacker to craft malicious file or directory names that manipulate the terminal after the program exits—potentially spoofing window titles, manipulating clipboard contents, or executing other terminal-dependent actions.

Technical details

This is a terminal escape sequence injection vulnerability in gdu's path output handling. When users exit the TUI (text user interface) mode, gdu prints directory and file paths to standard output without sanitizing embedded ANSI/VT100 escape sequences. An attacker can create directories or files with names containing terminal control sequences (e.g., `\x1b]0;...BEL` for title setting, `\x1b]52;c;...BEL` for clipboard manipulation). The vulnerability requires local access to create malicious filesystem entries, and exploitation occurs automatically when gdu prints the paths after TUI exit. No patch availability information is confirmed from the advisory text.

Affected products

  • dundee gdu <unknown

Timeline

  • 2026-08-13: disclosed

References