Executive brief
Shescape is a Node.js library that escapes user input to protect against shell injection attacks. On Unix systems using the Dash shell, the library fails to properly escape tilde (~) characters in variable assignments, allowing an attacker to disclose the user's home directory path. This could enable an attacker to redirect command operations to unexpected file locations.
Technical details
The vulnerability is an improper escaping issue (CWE-116, CWE-200) in Shescape's escape() and escapeAll() APIs when processing untrusted input in assignment contexts on Unix systems with Dash shell. The root cause is that tilde expansion is not properly handled during escaping, allowing the sequence `:~` to expand to `:` followed by the user's home directory. This requires the attacker to control input passed to these APIs and the application to use Dash shell (either explicitly configured or as the default). An attacker can extract the home directory path, and depending on command context, redirect operations to unexpected locations. The vulnerability has been patched in Shescape v2.1.14 and v3.0.1.
Affected products
- Shescape Shescape <2.1.14 || 3.0.0
Timeline
- 2026-07-24: disclosed
- 2026-07-24: patched: Patched in v2.1.14 and v3.0.1