THE ATTACKS THAT STILL WORK TODAY

The command you copy is not the command you run.

The worst terminal attack needs no hostile file - only your habit of copying a command from a web page. Try it below, then read the deception and clipboard classes that still work on a stock, up-to-date terminal today. Every one links a proof in the terminal-poc-corpus and an explainer on output lies - the sister site cataloguing how diffs, terminals and logs render bytes as instructions, whose Paste page is the fuller treatment of this very attack. For the side-by-side terminal verdicts, see the comparison.

Live demo: pastejacking

Here is a command a site might offer you. It reads echo "test". Copy it, then reveal what actually landed on your clipboard - here, or by pasting it into output-lies' x-ray tool. It is perfectly safe to run: every part is just echo.

echo "test"

You saw echo "test". Your clipboard held a whole second command chained on with && - echo "you did not expect this additional echo: unexpected code execution" - kept to a single line on purpose. Paste multiple lines and several terminals warn you: we tested it, and xfce4-terminal pops a "Warning: Potentially Unsafe Paste" dialog (its default, triggered by a newline in the paste), while qterminal offers a multiline-paste confirmation that is off by default. One line joined by && trips neither - it slips in silently and runs the moment you press Enter on a line you thought said only echo "test" (go ahead and run it - both halves are just echo). The page only ever shows echo "test"; the Copy button's JavaScript quietly writes the longer command to your clipboard instead, and slips a zero-width character in right at the && seam - it draws nothing, so a normal terminal shows no sign it is there. Real classes, not hypotheticals: this is pastejacking, and the same paste channel carries bracketed-paste bypass and Trojan Source tricks. The same channel is behind the in-the-wild ClickFix campaigns and the newline auto-run mechanism.

secure-terminal strips the smuggling. A paste carrying any invisible, control or bidi character is caught before it reaches your shell: secure-terminal names exactly what is hidden in it ("1 invisible character") and lets you drop it to plain ASCII or cancel - so nothing rides along unseen and the text you are about to run is fully visible to read first. It cannot judge a visible command for you - no terminal can, and a plain ASCII paste still submits - but it guarantees there is nothing hidden inside the paste. The corpus's adversarial harness feeds every one of these payloads to secure-terminal and asserts it neutralises each one.

And what still bites your terminal today

The paste above is one vector. These deception and clipboard classes still work on a stock, up-to-date terminal today - each links a proof in the corpus, an output-lies explainer, and the comparison matrix for the per-terminal verdict, with the "how secure-terminal handles it" answer in its own column.

Still-applicable issueWhat it doessecure-terminal
Trojan Source (bidi override) - CVE-2021-42574Bidirectional control characters reorder how a line renders, so the code you read is not the code that runs. Shown live in the combined board. Reach: any bidi-aware renderer - code hosts, editors, and terminals that implement bidi.Every bidi control renders as an inert, risk-coloured box or a named <U+202E> badge, so the reorder never happens (measured Safe) - dissected on output lies.
Homoglyph look-alikesNon-ASCII characters identical in shape to ASCII (Cyrillic a, Greek o) make a fake command or URL read as legitimate. Reach: universal.Every non-ASCII byte is tinted by risk class and can be named inline as <U+XXXX>, so a look-alike cannot pose as ASCII (measured Safe) - see it on output lies.
Invisible / zero-width charactersZero-width and other invisibles draw nothing, so a command or a paste can carry hidden bytes you never see (the demo above), and boxed in the combined board. Reach: universal.Each invisible byte is forced to a visible, inert box or named badge, in output and in a reviewed paste alike (measured Safe) - x-ray any string on output lies.
Clipboard hijack (OSC 52)A viewed file or a program's output silently overwrites your clipboard, so your next paste inserts attacker text. Reach: terminal-dependent - we measured it: konsole, alacritty and kitty write it by default; xterm/urxvt/st, qterminal and VTE (gnome/xfce4/mate) refuse; secure-terminal refuses too.Output can never write the system clipboard (measured Safe/off).
Title / tab hijack (OSC 0/2)Any output renames your window or tab to anything - a fake "production" label, a spoofed context. Reach: most terminals - shown live in the combined board (konsole and kitty are partial exceptions).The OS window title is never touched by output; a program-set title is shown only on the quarantined, untrusted tab line, so it cannot pose as a real label (quarantined).
Hyperlink spoof (OSC 8)A terminal hyperlink whose visible label reads example.com but whose real target is set separately in the escape, so the text you click is not where you go. Reach: any OSC 8-aware terminal - neutralized on output lies.Ships OSC 8 off by default, so the link is never made clickable and the raw target shows as inert text.
Escape repaint / cursor hide-textA cursor-up plus erase-line (or a stuck red-on-red colour) rewrites or conceals output already on screen, so a build log shows PASS over the real FAIL. Reach: every ANSI terminal - measured in the comparison.Parses no escape sequences (Not parsed) and its contrast guard forces any colour legible, so nothing a program prints can repaint the screen or reach a line already scrolled past.
Alt-screen forge (?1049h)Output switches to the alternate screen, paints a fake "ALL GREEN" dashboard, then leaves - restoring your scrollback so no trace remains. Reach: every terminal supports alt-screen; the deception is the forged paint.The default CLI line mode strips ?1049h and shows the log as inert text with scrollback intact; real full-screen programs need opt-in TUI mode.
Control bytes / NUL truncationC0/C1 control bytes truncate a line at a NUL, inject escapes, or forge the prompt. Reach: universal - a cheat-sheet class on output lies.Renders every control byte as an inert box named <U+XXXX> - nothing truncates, executes, or repaints (Not parsed).
Combining marks / Zalgo & fullwidth formsStacked combining marks (U+0300-036F) overflow a cell and disguise letters; fullwidth forms (U+FF01-FF5E) are wide look-alikes of ASCII. Reach: universal.Both are non-ASCII, so they show as inert risk-coloured boxes or named badges; heavy Zalgo collapses to boxes even in Show mode.
Notification spoof (OSC 9 / 99) - CVE-2022-41322Program output raises a desktop notification carrying attacker text. Reach: terminals that implement OSC 9/99.Keeps notifications off by default, so output can never raise one silently.
Clipboard read / query reflection (OSC 52 read, DA, answerback)Output asks the terminal to read your clipboard, or reflects a query (title, cursor, DECRQSS) back onto your shell's input. Reach: terminal-dependent - see the comparison.Interprets no escapes, so nothing on the output path can read the clipboard or write to the pty (measured Safe/off); clipboard read is off by default behind an ask-once-per-tab human gate.
ASCII look-alikes (rn = m)Pure ASCII, no Unicode at all: exarnple.com reads as example.com because rn looks like m. Reach: universal; unaffected by any byte-surfacing tool.Honest limit: no terminal, secure-terminal included, can flag this - there is nothing hidden in the bytes to surface. The only defense is reading character by character; the quiz trains it.
ClickFix / paste-and-run - T1204.004A fake CAPTCHA pre-loads a command onto your clipboard and tells you to paste it into a terminal. Actively exploited (Red Canary's #2 initial-access vector of 2025). Reach: in the wild now - see output lies: paste.The paste review bar holds every paste before a byte reaches the shell, names what is hidden, and gates the send button - a multi-line or invisible-laced paste cannot auto-run.
Bracketed-paste bypass - CVE-2021-31701An escape embedded in the paste closes the bracketed-paste guard early so the tail auto-runs. Reach: terminals relying on bracketed paste - how it slips through.Sanitizes every paste to reviewed ASCII and strips the guard-breaking escape (measured Safe), so the bypass has nothing to break.

secure-terminal closes these classes by design: non-ASCII becomes an inert, risk-coloured box (or a revealed <U+XXXX>), no escape sequence is parsed, the clipboard is never written from output, and the title is never touched - proven against each payload by the corpus's adversarial harness. The one it cannot close is the pure-ASCII look-alike (rn = m): no byte tool can, so read carefully.

The historical one: "a log file can run code"

For 20 years, some escape sequences asked the terminal a question - report the title, a DECRQSS status, the cursor - and the terminal answered by writing the reply into your shell's input. Chained with a newline, merely cat-ing a poisoned file could inject keystrokes and run a command. This is not a live threat on a current, default terminal: modern emulators mitigate it (empty or one-shot answerback, no auto-execute of replies, bracketed paste). We do not claim otherwise - the full CVE trail and a safe demo are on output lies (iTerm2, xterm, Windows Terminal, and the 2024 Ghostty / iTerm2 recurrence). It is worth naming only because the mechanism - output reflected onto the input wire - is the same one the reflection and input-injection rows measure.

How secure-terminal handles it: it parses no escape sequences at all, so the class cannot arise - there is nothing to reflect and nothing to auto-run (comparison). Proofs in the terminal-poc-corpus are canary-token only, never a live command.

The same lie, one layer over: code review

A terminal is not the only place untrusted bytes get rendered as something you trust. When you review a diff, the bidi, homoglyph, zero-width and control-byte tricks above ride in filenames, identifiers and branch names - and git adds its own: a submodule pointer bump, a retargeted symlink, an executable-bit flip, a .gitattributes that hides a file, a NUL that flips a source file to "binary". output-lies collects them as browsable, safe git branches: git diffs lie.

What secure-terminal does and does not do here. Viewing a hostile diff in secure-terminal neutralizes the display-layer bytes - a bidi filename, a homoglyph identifier, a zero-width split or a spoofed ref name arrives marked, not rendered. But the git-semantic traps (a mode bit, a submodule pointer, a .gitattributes) are not a display problem a terminal can judge - those need the safe git review drivers from Kicksecure's helper-scripts, which neutralize, surface, and fail closed. Same principle, different tool.

Test yourself, and test your own tools

Every class above is caught the same way: surface the raw bytes instead of trusting what they render to. Paste any URL, filename or command into output-lies' x-ray tool to see every hidden codepoint named, build a trap and fire it at the tools you already trust, or take the spot-the-lie quiz. secure-terminal is the same defense made the default for a whole session: paste in, read out, every invisible, bidi or look-alike byte arrives marked.