Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6xj8-qv9j-xcjq | Oh My Posh: Arbitrary command execution via template injection in the path segment |
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jandedobbeleer
Jandedobbeleer oh-my-posh |
|
| Vendors & Products |
Jandedobbeleer
Jandedobbeleer oh-my-posh |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1. | |
| Title | Oh My Posh: Arbitrary command execution via template injection in the path segment | |
| Weaknesses | CWE-1336 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T15:18:34.824Z
Reserved: 2026-08-12T19:00:33.736Z
Link: CVE-2026-73505
Updated: 2026-08-13T15:18:26.301Z
Status : Received
Published: 2026-08-13T15:20:16.943
Modified: 2026-08-13T16:19:04.977
Link: CVE-2026-73505
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:31:24Z
Github GHSA