CVE-2026-66486
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.<br />
<br />
<br />
<br />
<br />
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
Impact
Base Score 4.0
4.60
Severity 4.0
MEDIUM


