Source: rust-broot Version: 1.57.0+ds-2 Severity: important Tags: security upstream Forwarded: https://github.com/Canop/broot/issues/1188 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for rust-broot. CVE-2026-72847[0]: | broot renders each file and directory name in its interactive tree | view exactly as read from the filesystem. Names are converted with a | plain to_string_lossy() call in src/tree_build/builder.rs and in | TreeLine::unprune in src/tree/tree_line.rs, and no control-character | filtering exists anywhere in the code, even though the doc comment | on the TreeLine name field states that some characters may have been | stripped. Any local user who can create a file can therefore place | an escape sequence in its name and have it written unmodified to the | terminal of anyone who browses that directory, between broot's own | styling codes. A reported proof of concept used an OSC 52 clipboard- | write sequence and captured the raw bytes broot wrote to its pty, | confirming the sequence reaches the terminal unstripped. What an | injected OSC or CSI sequence can then do depends on the terminal | emulator in use. Browsing a directory is broot's primary function | and carries no expectation that the content is trusted. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-72847 https://www.cve.org/CVERecord?id=CVE-2026-72847 [1] https://github.com/Canop/broot/issues/1188 [2] https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5 [3] https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

