High severity8.1NVD Advisory· Published Jun 26, 2018· Updated Jun 17, 2026
CVE-2018-1000523
CVE-2018-1000523
Description
topydo contains a CWE-20: Improper Input Validation vulnerability in ListFormatParser::parse, file topydo/lib/ListFormat.py line 292 as of d4f843dac71308b2f29a7c2cdc76f055c3841523 that can result in Injection of arbitrary bytes to the terminal, including terminal escape code sequences. This attack appear to be exploitable via The victim must open a todo.txt with at least one specially crafted line..
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
topydoPyPI | <= 0.13 | — |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-h6h9-pphv-m266ghsaADVISORY
- github.com/bram85/topydo/blob/master/topydo/lib/ListFormat.pynvdThird Party AdvisoryWEB
- github.com/bram85/topydo/issues/240nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000523ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/topydo/PYSEC-2018-76.yamlghsaWEB
News mentions
0No linked articles in our index yet.