# CVE-2026-75483

## Summary

- **CVE ID:** CVE-2026-75483
- **Severity:** MEDIUM
- **CVSS Score:** 4.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-150
- **Published:** Aug 17, 2026
- **Last Modified:** Aug 20, 2026

## Description

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit arbitrary terminal control sequences on each prompt render when the shell enters affected directories.

## Affected Products

- romkatv — powerlevel10k (0)

## References

- [CNA](https://github.com/romkatv/powerlevel10k/issues/2961)
- [CNA](https://github.com/romkatv/powerlevel10k)
- [CNA](https://github.com/romkatv/powerlevel10k/commit/58e13d16a50e1d6908e39e20a670896808ccf350)
- [CNA](https://github.com/romkatv/powerlevel10k/blob/master/internal/p10k.zsh)
- [CNA](https://www.vulncheck.com/advisories/powerlevel10k-control-character-injection-via-package-json-version)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._