GHSA-6v4m-fw66-8r4x: Shescape: Path disclosure on Unix with Zsh
This impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem.
In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information.
References
- github.com/advisories/GHSA-6v4m-fw66-8r4x
- github.com/ericcornelissen/shescape/blob/dea8893a5877893d8d4923dbf253080e08899e6d/docs/migration.md
- github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de
- github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f
- github.com/ericcornelissen/shescape/pull/2649
- github.com/ericcornelissen/shescape/pull/2651
- github.com/ericcornelissen/shescape/releases/tag/v2.1.14
- github.com/ericcornelissen/shescape/releases/tag/v3.0.1
- github.com/ericcornelissen/shescape/security/advisories/GHSA-6v4m-fw66-8r4x
Code Behaviors & Features
Detect and mitigate GHSA-6v4m-fw66-8r4x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →