PT-2026-71290 · Shescape · Shescape

CVE-2026-73412

·

Published

2026-07-24

·

Updated

2026-08-12

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Shescape versions prior to 2.1.14 Shescape versions prior to 3.0.1
Description This issue affects users on Unix systems where the shell is explicitly configured to Zsh or the default shell is Zsh when using the escape() and escapeAll() functions. The problem is exacerbated by the Zsh options EXTENDED GLOB and MAGIC EQUAL SUBST. An attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system, which may lead to further information leakage depending on the command executed.
Recommendations Update to version 2.1.14. Update to version 3.0.1.

Exploit

Fix

Improper Neutralization of Wildcards

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73412
GHSA-6V4M-FW66-8R4X

Affected Products

Shescape