Security Advisory

CVE-2026-75483

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 20:36:08
Last updated 2026-08-18 00:44:22
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.