Executive brief
Shescape is a JavaScript library used to defend applications against shell injection attacks by safely escaping user input. A flaw in the library fails to escape null characters, allowing attackers to bypass its protection mechanism and execute arbitrary shell commands if they can inject null bytes into input.
Technical details
The vulnerability is an incomplete input sanitization flaw in Shescape's quote() function (CWE-88). The library failed to escape null characters (\x00) in shell command arguments, allowing them to pass through to the shell unfiltered. An attacker who can control user input can inject a null byte followed by arbitrary shell commands. The vulnerability affects all versions prior to 1.1.3, is network-reachable if the application processes untrusted input, and allows command execution depending on application context and shell behavior. The patch in v1.1.3 properly escapes null characters.
Affected products
- Eric Cornelissen Shescape < 1.1.3
Timeline
- 2021-03-13: disclosed
- 2021-03-18: patched: v1.1.3 released