CVE-2026-73412CWE-155CWE-78command-injection

CVE-2026-73412

published August 13, 2026

CVSS
6.3
EPSS
0%
Percentile
27.7
In the wild
Unconfirmed
What it is

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem. In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information. This issue is fixed in versions 2.1.14 and 3.0.1.

The record
Technical detail
CVSS
6.3 · NONE
CVSS v4.0
Not supplied
EPSS
0.00348 · 27.7th percentile
Weaknesses
CWE-155 · Improper Neutralization of Wildcards or Matching Symbols; CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published
2026-08-13T00:17Z
References (7)
EPSS history
Timeline
  • 12 AUG 19:38Z
    Shescape: Path disclosure on Unix with Zsh
    cvelistv5