powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.
https://github.com/romkatv/powerlevel10k/issues/2961
https://github.com/romkatv/powerlevel10k/commit/58e13d16a50e1d6908e39e20a670896808ccf350
https://github.com/romkatv/powerlevel10k/blob/master/internal/p10k.zsh
Published: 2026-08-17
Updated: 2026-08-17
Base Score: 2.1
Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N
Severity: Low
Base Score: 3.3
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Severity: Low
Base Score: 4.8
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Severity: Medium