Junglewise Threat Intelligence

JanDeDobbeleer Oh My Posh template injection in path segment

Severity: high · CVSS 7.8 · Published 2026-07-24

Technologies: github.com/jandedobbeleer/oh-my-posh (Go). Vendors: Go.

Executive brief

Oh My Posh is a popular tool used to customize command-line prompts. A security flaw allows an attacker to execute malicious commands on a user's computer if the user navigates into a folder with a specially crafted name (for example, in a downloaded ZIP file or a cloned code repository). This could allow an attacker to steal data, install malware, or gain full control over the user's session.

Technical details

A template injection vulnerability exists in the path segment of Oh My Posh. The application uses the Go 'text/template' engine to re-render the resolved path string, which includes raw folder names from the filesystem. Because the template engine's function map includes a 'cmd' function, an attacker can craft a directory name containing Go template syntax (e.g., '{{ cmd `whoami` }}') that executes arbitrary OS commands when the prompt renders. This occurs whenever the user's shell is inside or below the malicious directory. The vulnerability is present in the default configuration and affects all path styles. A fix is available in version 29.35.1.

Affected products

  • JanDeDobbeleer oh-my-posh <= 29.35.0

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: patched: Fixed in version 29.35.1
  • 2026-07-24: advisory

References

Related threats