it's worse with web stuff though... and it's a real vector.
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=terminal+es...
https://packetstormsecurity.com/files/162518/AWS-CloudShell-...
https://nvd.nist.gov/vuln/detail/CVE-2017-0899
https://github.com/InfosecMatter/terminal-escape-injections