{"apiVersion":"1.0","identifier":"CVE-2026-81694","description":"openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command-s output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().","publishedAt":"2026-08-27T17:20:59","lastModifiedAt":"2026-08-27T17:20:59","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81694","cvssScore":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","epssProbability":0.00177,"riskScore":0.34,"affectedProduct":"openssl_encrypt","affectedVersions":"<=1.4.8","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-81694","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-81694","en":"https://www.redsauce.net/en/cves/CVE-2026-81694","fr":"https://www.redsauce.net/fr/cves/CVE-2026-81694","pt":"https://www.redsauce.net/pt/cves/CVE-2026-81694","de":"https://www.redsauce.net/de/cves/CVE-2026-81694","sk":"https://www.redsauce.net/sk/cves/CVE-2026-81694","el":"https://www.redsauce.net/el/cves/CVE-2026-81694"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-81694"}}