Command Injection Affecting shescape package, versions <2.1.14>=3.0.0 <3.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Command Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-SHESCAPE-18752072
  • published13 Aug 2026
  • disclosed12 Aug 2026
  • creditoran-s

Introduced: 12 Aug 2026

NewCVE-2026-73412  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade shescape to version 2.1.14, 3.0.1 or higher.

Overview

shescape is a simple shell escape library

Affected versions of this package are vulnerable to Command Injection in the escape and escapeAll functions when used on Unix systems with the shell explicitly configured to Zsh, or when the default shell is Zsh. An attacker can obtain lists of files and directories on the system by leveraging home directory expansion and extended glob syntax.

Note: This is only exploitable if the shell is set to Zsh and the Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST are enabled.

CVSS Base Scores

version 4.0
version 3.1