---
title: "CVE-2026-48813\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-48813?format=md
keywords: index, follow
---

# CVE-2026-48813

Publication date 11 August 2026

Last updated 19 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++
source code. Versions prior to 2.0.20 have an improper input neutralization
issue leading to output manipulation, specifically, Terminal/ANSI Escape
Sequence Injection and XML Injection. A malicious file whose name contains
ANSI escape sequences can end up being included in flawfinder's standard
terminal output, with many effects. Untrusted fields (such as filenames,
categories, or code context text) were not properly sanitized when
generating structured reports. An attacker could exploit this to corrupt
CSV formats or inject arbitrary XML attributes into SonarQube outputs via
output\_sonar(). It impacts those who use flawfinder to evaluate
intentionally malicious filenames or file contents. This issue has been
fully patched in Version 2.0.20 (released 2026-05-16). There is no
configuration-based workaround within older versions of flawfinder. If an
immediate upgrade is not possible, users can mitigate the risk by
pre-scanning filenames, inspecting raw output, and/or restricting untrusted
inputs.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| flawfinder | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

8.7 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | None |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | High |
  | Vulnerable system - Availability impact | None |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.7 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48813)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-48813)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-48813)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-48813)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-48813>
* <https://github.com/david-a-wheeler/flawfinder/security/advisories/GHSA-4c3c-r6p8-c863>
