CVE-2026-48813 is an improper input neutralization vulnerability in Flawfinder, a static analysis tool for C/C++ source code, affecting versions prior to 2.0.20. The flaw arises because untrusted fields, including filenames, categories, and code context text, were not properly sanitized before being emitted in terminal output and structured report formats. As a result, specially crafted input can trigger Terminal/ANSI escape sequence injection in console output, corrupt CSV-formatted reports, and inject arbitrary XML attributes into SonarQube-compatible output generated via output_sonar(). The vulnerability is primarily exposed when Flawfinder is used to analyze intentionally malicious filenames or source content, allowing attacker-controlled data to manipulate how scan results are rendered or interpreted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small two-file repository containing a Bash proof-of-concept (`POC.sh`) and explanatory documentation (`README.md`). The exploit demonstrates a local/file-based terminal escape sequence injection against Flawfinder 2.0.19: it creates `/tmp/ff-poc`, then writes a C file whose filename itself contains ANSI escape bytes (`ESC`, `CR`, `BEL` variables are defined, though BEL is unused). The crafted filename ends with `genuine.c` so Flawfinder scans it, while the embedded control sequences reset formatting, carriage-return, clear the line, print a green fake status message (`[OK] flawfinder: no security issues found`), and hide subsequent text. The file contents intentionally include an unsafe `strcpy` call to prove that real findings exist but can be visually suppressed in terminal output. README states the issue affects Flawfinder 2.0.19 when output is viewed in libvte-based terminals such as mate-terminal on Parrot OS, was fixed in 2.0.20, and can also affect `--csv` output presentation. There is no remote communication, no shellcode, and no code execution payload; the capability is output spoofing / analyst deception during local security review.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.