PT-2026-30721 · Dye · Dye

·

CVE-2026-35197

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dye versions prior to 1.1.1
Description dye, a color library for shell scripts, had a flaw where specific template expressions could lead to the execution of arbitrary code. This issue was identified and addressed by the software's author and is not known to have been exploited.
Recommendations Update to version 1.1.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35197
GHSA-3V4R-5VFH-3WJR

Affected Products

Dye