CVE-2026-103431
Received Received - Intake

colmux Terminal Escape Sequence Injection in collectl

Vulnerability report for CVE-2026-103431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fedora Project

Description

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-150 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances. A local user on a monitored host can inject escape sequences into the terminal of an operator running colmux by crafting a malicious process name (argv[0]).

Detection Guidance

Check the version of collectl installed on your system. If it is below 4.3.20.2, the system is vulnerable. Run 'collectl --version' to check. Also, monitor network traffic on TCP port 2555 for unexpected data containing ANSI/VT100 escape sequences.

Impact Analysis

An attacker could manipulate the operator's screen, clear the display, move the cursor, or execute arbitrary commands depending on the terminal's capabilities. This could lead to unauthorized actions or data exposure if the operator pastes unseen clipboard content into a shell.

Compliance Impact

This vulnerability primarily affects terminal session integrity rather than direct data confidentiality or privacy. While it could enable screen manipulation or command execution, it does not inherently violate GDPR or HIPAA unless such actions lead to unauthorized access to personal or health data. Compliance risks arise if the exploit allows attackers to bypass security controls or access sensitive monitoring data.

Mitigation Strategies

Upgrade collectl to version 4.3.20.2 or later. If upgrading is not immediately possible, disable the colmux utility or restrict access to TCP port 2555. Avoid using colmux on untrusted networks until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart