• Sources: Oh My Posh advisory GHSA-6xj8-qv9j-xcjq, Oh My Posh advisory GHSA-fwjx-9p69-h25h, Oh My Posh 29.35.1 release
  • Summary: An advisory published 2026-07-24 reports that the Oh My Posh prompt engine re-renders the resolved path string, built from raw folder names read off the filesystem, through Go's text/template engine. That template function map exposes a cmd function that runs OS commands, so a directory whose name contains a template expression is evaluated when the prompt renders, giving arbitrary command execution as the current user once the shell is inside or below that directory. The advisory states the built-in default configuration is affected and that the render runs after the path-style switch unconditionally, so every path style is affected. Versions up to and including 29.35.0 are vulnerable and 29.35.1 is the fix. A companion moderate advisory covers terminal escape sequence injection through unsanitized prompt segment data, fixed in the same release.
  • Why it matters: Cloning an untrusted repository and changing into a directory is enough to reach code execution, which is a lower bar than opening a file in an editor or running a build.
  • Follow-up: Watch for a CVE assignment against GHSA-6xj8-qv9j-xcjq.

send feedback on this story