discovered 03 Aug 2026
CVE-2024-28085
→ View on GitHubWall-Escape (CVE-2024-28085) is an exploit tool designed to leverage a vulnerability in the util-linux wall command that allows attackers to inject escape sequences into command line arguments, potentially leaking sensitive information such as user passwords. The tool sets up an environment to execute commands while monitoring for password input, effectively capturing credentials during user interactions—particularly in contexts like SSH login or sudo commands. Notable features include the ability to manipulate command outputs and create a fake prompt that misleads users into revealing their passwords.