9.3
CVE-2026-81696
- EPSS 0.18%
- Veröffentlicht 27.08.2026 14:50:59
- Zuletzt bearbeitet 01.09.2026 20:21:05
- Erkennungen
openssl_encrypt before 1.4.9 Terminal Injection via info Command
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jahlives ≫ Openssl Encrypt SwPlatform python Version < 1.4.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.073 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-117 Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-539p-fxf4-7fv8
https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-terminal-injection-via-info-command