CVE-2026-26982 impacts the Ghostty terminal emulator, where it allows control characters in pasted or dropped text, potentially enabling arbitrary command execution in some shell environments. This is a high-severity vulnerability (CVSS 8.8) that requires user interaction, as an attacker must convince a user to copy and paste or drag and drop malicious, often invisible, text. The hidden nature of these dangerous characters makes detection difficult, posing a significant risk of full system compromise. Currently, there is no evidence of active exploitation, nor is public exploit code available. Users are strongly advised to update to Ghostty v1.3.0 or later to remediate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:ghostty:ghostty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.