CVE-2024-56803 - CVE House
Back to Database
Status published Medium CVE-2024-56803

Ghostty improperly handles window title sequences which can lead to arbitrary command execution

Vulnerability Description

Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. This attack requires an attacker to send malicious escape sequences followed by convincing the user to physically press the "enter" key. Fixed in Ghostty v1.0.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-56803

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ghostty-org

View all reports →

Affected Software

ghostty
Vulnerable Versions:
< 1.0.1

Timeline

Official Publish: December 31st, 2024
Last Modified: January 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)