CVE-2026-73412
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem. In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information. This issue is fixed in versions 2.1.14 and 3.0.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.35%
- CWE
- CWE-78, CWE-155
- Published
- 2026-08-12
- Last modified
- 2026-08-13
Affected products
- ericcornelissen shescape
- ericcornelissen shescape
Weakness type
Related vulnerabilities
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-88282 — GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
- CVE-2026-88277 — GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
- CVE-2026-88276 — GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection
- CVE-2026-88275 — GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
- CVE-2026-88274 — GV-LPC2011/LPC2211 - Wireless SSID Command Injection
- CVE-2026-88273 — GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
- CVE-2026-88272 — GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection