{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pickem--1.0.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pickem (\u003c 1.0.7)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe npm package \u003ccode\u003epickem\u003c/code\u003e contains a vulnerability (fixed in version 1.0.7) where item text, including labels, descriptions, and meta fields, is rendered to the terminal without adequate sanitization of escape sequences. Because this library is frequently used in CLI tools to display potentially untrusted input - such as git branch names, pull request titles, or API query results - it is susceptible to terminal injection. Attackers can leverage this by crafting malicious strings containing ANSI or C0 escape sequences. These sequences can be used to perform unauthorized OSC 52 clipboard writes, effectively staging malicious commands in the user's clipboard for later execution, or by spoofing the terminal UI to deceive users into believing they are interacting with legitimate or trusted system prompts. The vulnerability arises because previous sanitization logic only targeted active rows and failed to account for bare C0 control characters, leaving the system open to various manipulation techniques across multiple prompt types.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for remote execution (via clipboard-to-shell injection), interface manipulation, and denial-of-service via terminal flooding. Any CLI tool incorporating \u003ccode\u003epickem\u003c/code\u003e to display untrusted external data is at risk. If successful, an attacker can modify the user's local clipboard content, overwrite displayed UI text to hide malicious entries, or forge trust markers, which may lead to system compromise when a user inadvertently executes injected commands.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u003ccode\u003epickem\u003c/code\u003e package to version 1.0.7 or later immediately to incorporate the \u003ccode\u003esanitizeDisplay()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eFor applications using \u003ccode\u003epickem\u003c/code\u003e where upgrading is not possible, implement custom sanitization to strip all C0/C1/DEL control characters and ANSI escape sequences from any untrusted strings before passing them to the library.\u003c/li\u003e\n\u003cli\u003eReview CLI tools that pipe untrusted metadata (like git refs or API response fields) into interactive terminal displays to ensure they implement input sanitization.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T18:51:00Z","date_published":"2026-08-25T18:51:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pickem-terminal-injection/","summary":"The pickem npm package fails to sanitize item text labels, allowing attackers to perform terminal injection via OSC 52 clipboard writes or UI spoofing.","title":"Terminal Escape-Sequence Injection in pickem npm Package","url":"https://feed.craftedsignal.io/briefs/2026-08-pickem-terminal-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Pickem (\u003c 1.0.7)","version":"https://jsonfeed.org/version/1.1"}