-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper neutralization of ANSI escape sequences in user-controlled input. Based on standard Rust application structure and the described attack vector (message rendering), the most likely vulnerable components are: 1) The message handling function that receives untrusted input, and 2) The terminal output rendering component that displays content. These would be common locations where raw message data interacts with terminal interfaces without proper sanitization. Confidence is medium due to lack of direct code access, but grounded in the described vulnerability pattern and Rust crate architecture.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| gurk | rust | <= 0.6.3 |
Ongoing coverage of React2Shell