CVE-2024-56803

Publication date 31 December 2024

Last updated 23 April 2026


Ubuntu priority

Description

Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. This attack requires an attacker to send malicious escape sequences followed by convincing the user to physically press the "enter" key. Fixed in Ghostty v1.0.1.

Status

Package Ubuntu Release Status
ghostty 26.04 LTS resolute
Needs evaluation
25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release


Access our resources on patching vulnerabilities