{"api_version":"1","generated_at":"2026-07-24T18:51:27+00:00","cve":"CVE-2020-26283","urls":{"html":"https://cve.report/CVE-2020-26283","api":"https://cve.report/api/cve/CVE-2020-26283.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-26283","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-26283"},"summary":{"title":"CVE-2020-26283","description":"go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-03-24 21:15:00","updated_at":"2021-03-27 01:45:00"},"problem_types":["CWE-116"],"metrics":[],"references":[{"url":"https://github.com/ipfs/go-ipfs/pull/7831","name":"https://github.com/ipfs/go-ipfs/pull/7831","refsource":"MISC","tags":[],"title":"Escape non-printable characters in user output by gammazero · Pull Request #7831 · ipfs/go-ipfs · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a","name":"https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a","refsource":"MISC","tags":[],"title":"Merge pull request #7831 from ipfs/fix/escape-nonprintable-chars · ipfs/go-ipfs@fb0a9ac · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm","name":"https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm","refsource":"CONFIRM","tags":[],"title":"Control character injection in console output · Advisory · ipfs/go-ipfs · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-26283","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26283","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"26283","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"protocol","cpe5":"go-ipfs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-26283","qid":"501565","title":"Alpine Linux Security Update for go-ipfs"},{"cve":"CVE-2020-26283","qid":"502875","title":"Alpine Linux Security Update for kubo"},{"cve":"CVE-2020-26283","qid":"505756","title":"Alpine Linux Security Update for kubo"},{"cve":"CVE-2020-26283","qid":"982071","title":"Go (go) Security Update for github.com/ipfs/go-ipfs (GHSA-r4gv-vj59-cccm)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-26283","STATE":"PUBLIC","TITLE":"Control character injection in console output"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"go-ipfs","version":{"version_data":[{"version_value":"< 0.8.0"}]}}]},"vendor_name":"ipfs"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-116 Improper Encoding or Escaping of Output"}]}]},"references":{"reference_data":[{"name":"https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm","refsource":"CONFIRM","url":"https://github.com/ipfs/go-ipfs/security/advisories/GHSA-r4gv-vj59-cccm"},{"name":"https://github.com/ipfs/go-ipfs/pull/7831","refsource":"MISC","url":"https://github.com/ipfs/go-ipfs/pull/7831"},{"name":"https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a","refsource":"MISC","url":"https://github.com/ipfs/go-ipfs/commit/fb0a9acd2d8288bd1028c3219a420de62a09683a"}]},"source":{"advisory":"GHSA-r4gv-vj59-cccm","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-03-24 21:15:00","lastModifiedDate":"2021-03-27 01:45:00","problem_types":["CWE-116"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:protocol:go-ipfs:*:*:*:*:*:*:*:*","versionEndExcluding":"0.8.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"26283","Ordinal":"187705","Title":"CVE-2020-26283","CVE":"CVE-2020-26283","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"26283","Ordinal":"1","NoteData":"go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"26283","Ordinal":"2","NoteData":"2021-03-24","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"26283","Ordinal":"3","NoteData":"2021-03-24","Type":"Other","Title":"Modified"}]}}}