Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to...
Critical severity
Unreviewed
Published
Aug 16, 2026
to the GitHub Advisory Database
•
Updated Aug 16, 2026
Description
Published by the National Vulnerability Database
Aug 15, 2026
Published to the GitHub Advisory Database
Aug 16, 2026
Last updated
Aug 16, 2026
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.
References