OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103431

HIGH · CVSS 7.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The colmux tool in collectl versions prior to 4.3.20.2 is vulnerable to injection of ANSI/VT100 terminal escape sequences due to inadequate sanitization of data from remote instances. This flaw allows a local user on a monitored host to manipulate the terminal display of an operator running colmux, potentially leading to unauthorized command execution or information disclosure. Organizations using collectl for performance monitoring should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-103431
Severity
HIGH
CVSS
7.7
EPSS
0.18%

Original NVD Description

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).