Junglewise Threat Intelligence

CVE-2026-81707: openssl_encrypt ANSI escape injection in identity email

CVE-2026-81707 · Severity: critical · CVSS 9.8 · Published 2026-08-27

Technologies: Jahlives Openssl Encrypt. Vendors: Jahlives.

Executive brief

openssl_encrypt is a cryptographic tool that manages identity documents and cryptographic keys. A vulnerability in versions before 1.4.9 allows attackers to inject special control characters into the email field of identity bundles, enabling them to forge the fingerprint verification display that users rely on to confirm they have the correct key. An attacker can deliver a malicious identity bundle through normal key-exchange flows, tricking users into trusting an attacker's key instead of the legitimate one—undermining the out-of-band verification mechanism designed to prevent key substitution attacks.

Technical details

The vulnerability is an improper input validation and inadequate output sanitization issue (CWE-20, CWE-150) in the Identity.import_public function and related identity display code. The email field of imported identity documents is accepted and printed to the terminal completely unsanitized, allowing JSON-encoded ANSI escape sequences (\u001b) to be injected. An attacker can craft a malicious bundle with escape sequences in the email field that move the cursor and overwrite the genuine "Fingerprint:" verification line with an attacker-chosen fingerprint. The attack is reachable via normal contact-exchange flows (file imports, GUI paste) and keyserver responses without authentication. The fix (available in version 1.4.9) validates all identity metadata at import boundaries and implements a display sanitizer that escapes control characters and special sequences at every terminal output point.

Affected products

  • jahlives openssl_encrypt before 1.4.9

Timeline

  • 2026-08-27: disclosed: CVE-2026-81707 and GHSA-qjr2-x6mr-8xgf published
  • 2026-08-12: patched: Patched in version 1.4.9

References

Related threats