Executive brief
Shescape is a JavaScript library used to safely escape user input for use in shell commands. A vulnerability in the library's Windows Command Prompt (CMD) handling allows an attacker to bypass security filters and read sensitive environment variables from the host system. This could lead to the exposure of system paths, configuration details, or other sensitive data stored in the environment.
Technical details
Shescape fails to properly escape the percent sign (%) when used with the Windows Command Prompt (cmd.exe). When the 'interpolation' option is set to true in functions like quote, quoteAll, escape, or escapeAll, an attacker can provide a payload containing environment variable syntax (e.g., %PATH%). Because the library does not sanitize or escape these characters correctly for the CMD shell, the underlying system expands the variable, allowing the attacker to read its contents. This is classified as CWE-526 (Exposure of Sensitive Information Through Environmental Variables). The issue is fixed in version 1.7.1 by implementing proper percent-sign escaping.
Affected products
- ericcornelissen shescape < 1.7.1
Timeline
- 2023-06-21: patched: Fix released in version 1.7.1
- 2023-06-22: disclosed: Security advisory published
References
- https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r
- https://github.com/ericcornelissen/shescape/pull/982
- https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac
- https://github.com/ericcornelissen/shescape
- https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1