PT-2026-73059 · Shescape · Shescape

·

CVE-2026-73055

·

Published

2026-08-15

·

Updated

2026-08-26

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Shescape versions prior to 2.1.15 Shescape versions 3.0.0 through 3.0.1
Description On Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox, the software fails to properly escape tilde (~) characters in assignment contexts. An attacker providing untrusted input to the escape() and escapeAll() APIs in an assignment prefixed to a command can inject a tilde payload. This can lead to the disclosure of the user's home directory location or alter the directory where a command operates.
Recommendations Update Shescape to version 2.1.15 or later. Update Shescape to version 3.0.2 or later.

Exploit

Fix

Information Disclosure

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73055
GHSA-J44H-FQHH-FH28

Affected Products

Shescape