#1145024 rust-broot: CVE-2026-72847

Package:
src:rust-broot
Source:
src:rust-broot
Submitter:
Salvatore Bonaccorso
Date:
2026-08-21 14:15:02 UTC
Severity:
normal
Tags:
#1145024#5
Date:
2026-08-21 14:12:00 UTC
From:
To:
Hi,

The following vulnerability was published for rust-broot.

CVE-2026-72847[0]:
| broot renders each file and directory name in its interactive tree
| view exactly as read from the filesystem. Names are converted with a
| plain to_string_lossy() call in src/tree_build/builder.rs and in
| TreeLine::unprune in src/tree/tree_line.rs, and no control-character
| filtering exists anywhere in the code, even though the doc comment
| on the TreeLine name field states that some characters may have been
| stripped. Any local user who can create a file can therefore place
| an escape sequence in its name and have it written unmodified to the
| terminal of anyone who browses that directory, between broot's own
| styling codes. A reported proof of concept used an OSC 52 clipboard-
| write sequence and captured the raw bytes broot wrote to its pty,
| confirming the sequence reaches the terminal unstripped. What an
| injected OSC or CSI sequence can then do depends on the terminal
| emulator in use. Browsing a directory is broot's primary function
| and carries no expectation that the content is trusted.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-72847
https://www.cve.org/CVERecord?id=CVE-2026-72847
[1] https://github.com/Canop/broot/issues/1188
[2] https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
[3] https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore