CVE-2026-103431

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.7
HIGH

Description

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).

Published
October 1, 2026 9:17 AM
Last Modified
October 1, 2026 9:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-150

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.