Executive brief
Shescape is a library used to safely escape user input for use in shell commands. A vulnerability exists on Windows systems using the CMD shell where certain characters, specifically parentheses, are not properly handled. This could allow an attacker to bypass security filters and execute unauthorized commands on the underlying server, potentially leading to a full system takeover or data theft.
Technical details
A shell injection vulnerability exists in Shescape's 'escape' and 'escapeAll' APIs when used on Windows with the CMD shell. The root cause is the improper neutralization of parentheses '(' and ')', which can be used to break out of command contexts in CMD. An attacker can provide a crafted payload containing these characters to execute arbitrary commands if the escaped output is used within certain shell constructs (like 'if' statements). This affects configurations where the shell is explicitly set to 'cmd.exe' or defaults to it. The issue is patched in versions 2.1.14 and 3.0.1.
Affected products
- ericcornelissen shescape < 2.1.14, >= 3.0.0 < 3.0.1
Timeline
- 2026-07-23: disclosed
- 2026-07-24: advisory
- 2026-07-24: patched