CVE-2026-9323
Urwid Web Display Session ID Predictability and Exposure
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability exists in the Urwid web display backend due to predictable session identifiers generated using a non-cryptographically secure method. An attacker could observe session IDs or list temporary files to obtain them, then read terminal screens, inject keystrokes for code execution, or crash sessions. This im