← Back to CVE search

CVE-2026-35197

dye

Description

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye-s author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.

CVSS 6.6EPSS 0.291%Risk 0.68
View source
Published
2026-04-06 20:16:27
Affected versions
<1.1.1
Type
Package
Last modified
2026-07-24 21:10:00
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N