usage_rules is vulnerable to Terminal Escape Sequence Injection
23
Low Risk
The mix usage_rules.search_docs task queries search.hexdocs.pm and prints publisher controlled result fields such as title, package, ref, and highlight snippets to the terminal. A package published to Hex can embed ANSI and OSC escape sequences in its indexed documentation, and a search prints those sequences without stripping control characters. Those sequences can forge or hide output and, on terminals that support OSC 52, write to the clipboard. The fix adds a terminal_safe/1 helper that strips C0/C1 control characters from server supplied fields before printing.
You are affected if you are using a version that falls within the vulnerable range and you run the mix usage_rules.search_docs task.
usage_rules is vulnerable to Terminal Escape Sequence Injection in versions 0.1.18 - 1.2.7.
Upgrade the usage_rules library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.