Junglewise Threat Intelligence

Shescape path disclosure in Zsh shell escaping

Severity: medium · CVSS 6.3 · Published 2026-07-24

Technologies: Ericcornelissen Shescape.

Executive brief

Shescape is a library used to safely escape shell commands to prevent security vulnerabilities. A flaw exists when using the Zsh shell on Unix systems where certain characters are not properly neutralized. This allows an attacker to potentially view sensitive file paths or directory listings on the server, which could lead to further information disclosure.

Technical details

A path disclosure vulnerability exists in Shescape when configured to use Zsh on Unix-like systems. The library fails to properly neutralize characters like '~', '^', and '#' which Zsh interprets for home directory expansion and extended globbing. An attacker providing crafted input to the `escape` or `escapeAll` functions can trigger these shell expansions, leading to the disclosure of the user's home directory path or local file listings. The risk is increased if Zsh options like `EXTENDED_GLOB` or `MAGIC_EQUAL_SUBST` are enabled. The issue is patched in versions 2.1.14 and 3.0.1.

Affected products

  • ericcornelissen shescape < 2.1.14, >= 3.0.0, < 3.0.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-24: advisory
  • 2026-07-24: patched

References