THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8qx3-8gm5-9cj2 (high) — pickem vulnerable to terminal escape-sequence injection via unsanitized item text

[GHSA] GHSA-8qx3-8gm5-9cj2 (high) — pickem vulnerable to terminal escape-sequence injection via unsanitized item text

medgithub_advisoriesPublished 2026-08-25

GHSA-8qx3-8gm5-9cj2 Severity: high CVE: None

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

### Impact pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. `chrome.row` only stripped ANSI from the **active** row; inactive rows, the public `createFormatter`, and selection-summary lines printed

Original source: https://github.com/advisories/GHSA-8qx3-8gm5-9cj2