CVE-2026-73035
Last modified
CVE-2026-73035 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or --format repo option, unfiltered escape sequences are written directly to the terminal, enabling malicious output manipulation or other terminal-dependent effects.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or --format repo option, unfiltered escape sequences are written directly to the terminal, enabling malicious output manipulation or other terminal-dependent effects.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| raineorshine | npm-check-updates | <= 23.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-73035?
How severe is CVE-2026-73035?
How do I fix CVE-2026-73035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7303A security flaw has been discovered in Xuxueli xxl-job up to…3.7
- CVE-2026-73030unearth through 0.18.2, fixed in commit 6c78164, contains a …8.1
- CVE-2026-73031telegram-search contains a stored cross-site scripting vulne…8.7
- CVE-2026-73032PapersGPT for Zotero 0.6.1 contains a remote code execution …9.6
- CVE-2026-73033Sucuri Security WordPress plugin through version 2.7.3 conta…6.5
- CVE-2026-73034DB-GPT v0.8.1 contains an unauthenticated path traversal vul…9.8
- CVE-2026-73036Bash-it 3.2.0 contains a terminal escape sequence injection …4.4
- CVE-2026-73037Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cr…6.1
- CVE-2026-73038NodeBB before 4.15.0 contains a stored cross-site scripting …6.1
- CVE-2026-73039streama contains an insecure direct object reference vulnera…5.4
- CVE-2026-7304SGLangs multimodal generation runtime is vulnerable to unaut…9.8
- CVE-2026-73040Dockge validates a stack name only on the write path. In bac…8.8
Are you affected by CVE-2026-73035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
