Junglewise Threat Intelligence

CVE-2026-73505: GO-2026-6108 - Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

CVE-2026-73505 · Severity: low · CVSS 3.1 · Published 2026-08-18

Technologies: github.com/jandedobbeleer/oh-my-posh (Go). Vendors: Go.

Executive brief

Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh

Affected products

  • Go github.com/jandedobbeleer/oh-my-posh

Related threats