The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade shescape to version 2.1.14, 3.0.1 or higher.
shescape is a simple shell escape library
Affected versions of this package are vulnerable to Command Injection in the escape and escapeAll functions when used on Unix systems with the shell explicitly configured to Zsh, or when the default shell is Zsh. An attacker can obtain lists of files and directories on the system by leveraging home directory expansion and extended glob syntax.
Note: This is only exploitable if the shell is set to Zsh and the Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST are enabled.