PT-2026-71290 · Shescape · Shescape
CVE-2026-73412
·
Published
2026-07-24
·
Updated
2026-08-12
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Shescape versions prior to 2.1.14
Shescape versions prior to 3.0.1
Description
This issue affects users on Unix systems where the shell is explicitly configured to Zsh or the default shell is Zsh when using the
escape() and escapeAll() functions. The problem is exacerbated by the Zsh options EXTENDED GLOB and MAGIC EQUAL SUBST. An attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system, which may lead to further information leakage depending on the command executed.Recommendations
Update to version 2.1.14.
Update to version 3.0.1.
Exploit
Fix
Improper Neutralization of Wildcards
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shescape