igniter is vulnerable to Terminal Escape Sequence Injection
23
Low Risk
The mix igniter.install confirmation panel prints publisher controlled Hex metadata such as the package description, owner usernames, dependency requirement names, and version. These fields reach the terminal with only newlines stripped, so a malicious or typosquatted package can embed ANSI escape sequences in its metadata. The sequences rewrite the panel to forge trusted author names and download counts and hide the real values, so the developer approves an untrusted dependency. The patch strips all Unicode control characters from every metadata field before printing them.
You are affected if you are using a version that falls within the vulnerable range and you run mix igniter.install to add a package from an untrusted publisher.
igniter is vulnerable to Terminal Escape Sequence Injection in versions 0.8.1 - 0.8.3.
Upgrade the igniter library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.