Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6xj8-qv9j-xcjq | Oh My Posh: Arbitrary command execution via template injection in the path segment |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1. | |
| Title | Oh My Posh: Arbitrary command execution via template injection in the path segment | |
| Weaknesses | CWE-1336 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T15:18:34.824Z
Reserved: 2026-08-12T19:00:33.736Z
Link: CVE-2026-73505
Updated: 2026-08-13T15:18:26.301Z
Status : Received
Published: 2026-08-13T15:20:16.943
Modified: 2026-08-13T16:19:04.977
Link: CVE-2026-73505
No data.
OpenCVE Enrichment
Updated: 2026-08-13T16:30:03Z
Github GHSA