colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-103431 is a terminal injection vulnerability in collectl's colmux component that fails to sanitize ANSI/VT100 escape sequences from remote monitoring data. When a local user on a monitored host crafts a malicious process name (argv[0]), these escape sequences pass through to the operator's terminal without sanitization, enabling arbitrary terminal manipulation. This affects system administrators and security teams using collectl for distributed system monitoring, where a compromised or malicious host can manipulate the operator's terminal environment—potentially obscuring logs, executing terminal commands, or exfiltrating sensitive information displayed on screen.
While this CVE currently maps to zero Casky skills due to its lack of MITRE ATT&CK technique classification, practitioners would detect this attack pattern through behavioral analysis of process execution and output handling. The vulnerability chain involves CWE-150 (Improper Neutralization of Input During Web Page Generation) and relies on tactics associated with execution evasion and credential access through terminal manipulation. Casky's Claude-powered analysis would identify suspicious process naming patterns combined with terminal control character sequences, flagging anomalous argv[0] values containing escape codes, unexpected terminal state changes during remote monitoring sessions, and correlation between process creation events on monitored hosts and terminal behavior anomalies on operator workstations—helping practitioners recognize when malicious actors attempt to abuse monitoring infrastructure for command injection or social engineering.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-103431. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation