—
GO-2026-6111
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
Quick fix
GO-2026-6111 — github.com/jandedobbeleer/oh-my-posh: upgrade to the fixed version with the command below.
go get github.com/jandedobbeleer/oh-my-posh@v29.35.1+incompatibleDetails
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/jandedobbeleer/oh-my-posh
Introduced in:
0Fixed in: 29.35.1+incompatibleFix
go get github.com/jandedobbeleer/oh-my-posh@v29.35.1+incompatibleReferences
- https://github.com/JanDeDobbeleer/oh-my-posh/security/advisories/GHSA-fwjx-9p69-h25h[ADVISORY]
- https://github.com/JanDeDobbeleer/oh-my-posh/commit/edcf3c88f3fb582e84358b385c49d33d04c04224[WEB]
- https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.35.1[WEB]
- https://github.com/JanDeDobbeleer/oh-my-posh/releases/tag/v29.36.0[WEB]