Junglewise Threat Intelligence

Shescape shell injection via unescaped parentheses in CMD on Windows

Severity: critical · CVSS 9.2 · Published 2026-07-24

Technologies: Ericcornelissen Shescape.

Executive brief

Shescape is a library used to safely escape user input for use in shell commands. A vulnerability exists on Windows systems using the CMD shell where certain characters, specifically parentheses, are not properly handled. This could allow an attacker to bypass security filters and execute unauthorized commands on the underlying server, potentially leading to a full system takeover or data theft.

Technical details

A shell injection vulnerability exists in Shescape's 'escape' and 'escapeAll' APIs when used on Windows with the CMD shell. The root cause is the improper neutralization of parentheses '(' and ')', which can be used to break out of command contexts in CMD. An attacker can provide a crafted payload containing these characters to execute arbitrary commands if the escaped output is used within certain shell constructs (like 'if' statements). This affects configurations where the shell is explicitly set to 'cmd.exe' or defaults to it. The issue is patched in versions 2.1.14 and 3.0.1.

Affected products

  • ericcornelissen shescape < 2.1.14, >= 3.0.0 < 3.0.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-24: advisory
  • 2026-07-24: patched

References