Intel

AIKIDO-2026-544074

igniter is vulnerable to Terminal Escape Sequence Injection

Terminal Escape Sequence InjectionCVE-2026-82584 Published Today

23

Low Risk

This Affects:

ELIXIRigniter
0.8.1 - 0.8.3
Fixed in 0.8.4
Are you affected? Scan for Free

TL;DR

The mix igniter.install confirmation panel prints publisher controlled Hex metadata such as the package description, owner usernames, dependency requirement names, and version. These fields reach the terminal with only newlines stripped, so a malicious or typosquatted package can embed ANSI escape sequences in its metadata. The sequences rewrite the panel to forge trusted author names and download counts and hide the real values, so the developer approves an untrusted dependency. The patch strips all Unicode control characters from every metadata field before printing them.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run mix igniter.install to add a package from an untrusted publisher.

Background info

igniter is vulnerable to Terminal Escape Sequence Injection in versions 0.8.1 - 0.8.3.

How to fix this

Upgrade the igniter library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform