Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m5p4-gvpx-4mvr | GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content |
Sat, 30 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datadoghq
Datadoghq guarddog |
|
| Vendors & Products |
Datadoghq
Datadoghq guarddog |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject ANSI or OSC escape sequences into analyst terminals or CI logs. | |
| Title | GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content | |
| Weaknesses | CWE-116 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T15:34:32.271Z
Reserved: 2026-05-08T16:23:33.263Z
Link: CVE-2026-44972
Updated: 2026-05-27T15:34:28.544Z
Status : Deferred
Published: 2026-05-27T15:16:29.690
Modified: 2026-06-17T10:51:33.040
Link: CVE-2026-44972
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:00:12Z
Github GHSA