An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/schollz/croc/v9(Go) | 0 | 9.6.16 | N/A |
CVSS Metrics