CVE-2026-44972

GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject ANSI or OSC escape sequences into analyst terminals or CI logs.
Configurations

No configuration.

History

27 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 15:16

Updated : 2026-05-29 15:39


NVD link : CVE-2026-44972

Mitre link : CVE-2026-44972

CVE.ORG link : CVE-2026-44972


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output