PT-2026-73059 · Shescape · Shescape
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shescape versions prior to 2.1.15
Shescape versions 3.0.0 through 3.0.1
Description
On Unix systems where the shell is explicitly configured to "sh" or true and
/bin/sh points to BusyBox, the software fails to properly escape tilde (~) characters in assignment contexts. An attacker providing untrusted input to the escape() and escapeAll() APIs in an assignment prefixed to a command can inject a tilde payload. This can lead to the disclosure of the user's home directory location or alter the directory where a command operates.Recommendations
Update Shescape to version 2.1.15 or later.
Update Shescape to version 3.0.2 or later.
Exploit
Fix
Information Disclosure
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shescape