CVE-2026-103431
Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
| CWE | CWE-150 |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new high vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
References
Credits
This issue was discovered by Laurence Oberman (Red Hat) and Nathan Scott (Red Hat).