Skip to main content
Vulnerability Database/CVE-2026-93421

CVE-2026-93421: Mesop ANSI Injection Vulnerability

CVE-2026-93421 is an ANSI injection flaw in Mesop that allows attackers to inject terminal control sequences through CSP reports. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-93421 Overview

CVE-2026-93421 is a log injection vulnerability [CWE-117] in Mesop, a Python-based UI framework for building web applications. Versions prior to 1.3.4 expose an unauthenticated /__csp__ endpoint that forwards attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py. The handler writes those values to standard output without stripping terminal control sequences. Operators reviewing the logs in an ANSI-capable terminal can be tricked by injected ANSI or VT100 sequences that clear the display, hide text, reposition the cursor, or present forged messages. The issue is fixed in version 1.3.4.

Critical Impact

Unauthenticated attackers can inject terminal escape sequences into Mesop server logs, degrading the integrity of monitoring output and incident-response workflows.

Affected Products

  • Mesop versions prior to 1.3.4
  • Mesop deployments exposing the /__csp__ endpoint
  • Operator workflows reading Mesop logs in ANSI-capable terminals

Discovery Timeline

  • 2026-09-23 - CVE-2026-93421 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-93421

Vulnerability Analysis

Mesop exposes an unauthenticated CSP violation reporting endpoint at /__csp__. The handler accepts a JSON body containing fields such as document-uri, blocked-uri, and violated-directive, and prints them to standard output for operator visibility. Because the handler performs no neutralization of control characters, an attacker can embed ANSI or VT100 escape sequences directly in the reported values.

When an operator later views the logs in a terminal that interprets these sequences, the injected payload executes as terminal control commands. This can clear the screen, overwrite prior lines, hide subsequent output, or render fabricated log entries that appear to originate from Mesop itself. The result is a loss of integrity in monitoring and incident-response output, which can mask malicious activity or mislead responders.

Root Cause

The root cause is improper output neutralization for logs [CWE-117]. The csp_report handler in mesop/server/static_file_serving.py writes untrusted request fields to standard output without filtering the ESC character (\\x1B) or other control sequences.

Attack Vector

Exploitation requires only a network-reachable Mesop instance and no authentication. An attacker sends a crafted POST request to /__csp__ containing ANSI escape sequences inside CSP report fields. The payload remains dormant in log storage until an operator opens the log in an interpreting terminal, at which point the escape sequences take effect.

python
# Patch excerpt: sanitize ANSI escape sequences before logging
# Matches ANSI CSI, OSC, and other common ANSI/VT100 escape sequences so they
# can be stripped from untrusted data before it's written to the terminal.
_ANSI_ESCAPE_RE = re.compile(
  r"""
    \\x1B
    (?:
        \[[0-?]*[ -/]*[@-~]              # CSI
      | \][^\\x07\\x1B]*(?:\\x07|\\x1B\\)    # OSC
      | [PX^_][^\\x1B]*\\x1B\\             # DCS/APC/PM/SOS
      | [@-_]                            # 2-byte escape
    )
    """,
  re.VERBOSE,
)


def _sanitize_terminal(value: object) -> str:
  # Prevent ANSI/VT100 terminal escape injection when logging
  # attacker-controlled data (e.g. CSP report fields).
  if not isinstance(value, str):
    value = str(value)
  return _ANSI_ESCAPE_RE.sub("", value)

Source: GitHub Commit f38c42a

Detection Methods for CVE-2026-93421

Indicators of Compromise

  • POST requests to the /__csp__ endpoint containing byte 0x1B (ESC) in the request body.
  • CSP report fields (document-uri, blocked-uri, violated-directive) containing bracketed control sequences such as \\x1B[2J or \\x1B[H.
  • Log files with truncated, overwritten, or visually manipulated entries when opened in a terminal viewer.

Detection Strategies

  • Inspect raw request bodies to /__csp__ for non-printable control characters before terminals interpret them.
  • Grep archived Mesop logs for the escape byte pattern (\\x1B\[) to identify historical injection attempts.
  • Compare log rendering between a raw viewer (for example cat -v or less -R disabled) and a terminal viewer to reveal hidden content.

Monitoring Recommendations

  • Route Mesop server output to a centralized log platform that stores raw bytes and renders logs safely in a web UI.
  • Alert on any request to /__csp__ from unexpected external sources, since legitimate CSP reports originate only from browsers loading the app.
  • Track version inventory of Mesop deployments to confirm all instances are running 1.3.4 or later.

How to Mitigate CVE-2026-93421

Immediate Actions Required

  • Upgrade Mesop to version 1.3.4 or later, which introduces the _sanitize_terminal helper that strips ANSI, CSI, OSC, DCS, APC, PM, and SOS sequences.
  • Audit archived Mesop logs for embedded escape sequences and rotate any logs that may contain forged entries.
  • Restrict network access to the /__csp__ endpoint where possible, for example behind an authenticated ingress or WAF.

Patch Information

The fix is delivered in Mesop 1.3.4 via pull request #1397 and commit f38c42a. See the GitHub Security Advisory GHSA-g7f6-rxc4-qhph and the v1.3.4 release notes for full details.

Workarounds

  • View Mesop logs only through tools that render control characters as literal text, such as cat -v or a web-based log viewer.
  • Deploy a reverse proxy rule that rejects requests to /__csp__ containing the 0x1B byte in the body.
  • Disable or block the /__csp__ endpoint at the network layer if CSP reporting is not required.
bash
# Upgrade Mesop to the patched version
pip install --upgrade 'mesop>=1.3.4'

# Verify the installed version
python -c "import mesop; print(mesop.__version__)"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.