Junglewise Threat Intelligence

CVE-2026-30916: Shescape shell misidentification via symlink chains

CVE-2026-30916 · Severity: medium · CVSS 4 · Published 2026-03-07

Technologies: shescape (npm). Vendors: npm.

Executive brief

Shescape is a Node.js library that escapes user input to prevent command injection attacks. A flaw in its shell detection logic could cause it to misidentify the shell type when the shell path points to a symlink chain, potentially allowing an attacker to bypass input escaping and execute unintended commands or expose sensitive data.

Technical details

This vulnerability stems from inadequate symlink resolution in Shescape's shell identification logic. When a shell executable path is configured as a symlink to another symlink (a chain), the library fails to correctly identify the actual shell type, leading to incorrect escaping rules being applied. An attacker who can influence the shell configuration (via symlink chains they control) can cause the library to apply escaping rules for the wrong shell, enabling command injection. The vulnerability requires specific system configuration (shell path pointing to a symlink chain) and affects versions prior to 2.1.9. A patch is available in v2.1.9 which properly resolves symlink chains.

Affected products

  • ericcornelissen shescape prior to 2.1.9

Timeline

  • 2026-03-07: disclosed
  • 2026-03-20: patched: v2.1.9 released with fix

References

Related threats