PT-2026-59169 · Pypi · Guarddog

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Summary

GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject ANSI or OSC escape sequences into analyst terminals or CI logs.

Description

The finding formatter stores file paths and snippets from scanned content:
python
location = file path + ":" + str(start line)
finding = {
  "location": location,
  "code": code,
  "message": result["extra"]["message"],
}
The human-readable reporter later prints these values directly:
python
" * " + finding["message"] + " at " + finding["location"] + "
  " + format code line for output(finding["code"])
No escaping is applied for control characters such as x1b. A malicious package can therefore ship a filename like:
text
evilx1b[2J.py
or matched source lines containing terminal escapes, which survive into the final CLI output.

Reproduction summary

  1. Create a file whose name contains x1b[2J.
  2. Feed a semgrep-style result referencing that file into Analyzer. format semgrep response().
  3. Render the result with HumanReadableReporter.print scan results().
  4. The output string contains the raw escape bytes, which a terminal may interpret.

Key code paths

  • guarddog/analyzer/analyzer.py:377-392
  • guarddog/reporters/human readable.py:36-42
  • guarddog/reporters/human readable.py:84-91

Practical impact

This can be used to:
  • clear or rewrite analyst terminal output
  • inject misleading or spoofed log content in CI
  • emit clickable OSC 8 hyperlinks or title changes in compatible terminals

Prior public disclosure check

As of 2026-03-18, no matching public GitHub advisory, CVE, or public repo issue was found for this specific bug.

Suggested fix

Escape or strip terminal control characters before rendering any attacker-controlled value in human-readable output. This should cover package names, file paths, messages, and code snippets.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2506

Affected Products

Guarddog