PT-2026-24114 · Ghostty · Ghostty

Shibaaa204

·

Published

2026-03-09

·

Updated

2026-03-19

·

CVE-2026-26982

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostty versions prior to 1.3.0
Description Ghostty allows control characters, such as 0x03 (Ctrl+C), within pasted or dropped text. These characters can be leveraged to execute arbitrary commands in certain shell environments. Successful exploitation requires an attacker to trick a user into copying and pasting or dragging and dropping malicious text. The dangerous characters are generally not visible in most graphical user interfaces, making detection difficult, particularly with complex strings.
Recommendations Update to Ghostty version 1.3.0 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-26982
GHSA-4JXV-XGRP-5M3R
OPENSUSE-SU-2026:10316-1

Affected Products

Ghostty