Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

shescape — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in shescape, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities associated with shescape, a software product developed by its respective vendor, categorized under generic weakness types. It aggregates data from multiple reputable sources to provide a comprehensive view of the security posture related to this specific tool. The content includes details on various vulnerability classes, such as buffer overflows, injection flaws, and logic errors, covering a wide historical range of disclosed issues from their initial public release up to the most recent patches. Here, users can track the vendor's advisory history to understand how quickly security flaws are identified and resolved. This resource allows developers and security analysts to understand specific weakness classes by examining real-world examples and exploit patterns. Furthermore, it enables users to look up the product's vulnerability history to assess risk over time and determine if legacy versions remain exposed. By centralizing this information, the page serves as a reference for impact analysis and mitigation planning. It is intended for technical professionals who need to evaluate the security implications of using shescape in their environments. The aggregated data highlights trends in vulnerability discovery and remediation, helping organizations make informed decisions about patching strategies and risk acceptance. No specific CVE identifiers are listed here to maintain a high-level overview, but detailed cross-references are available through linked advisory pages. This summary ensures that readers grasp the scope and relevance of the collected data without unnecessary technical clutter.

Vendor: ericcornelissen

CVE IDTitleCVSSSeverityPublished
CVE-2026-73055 Shescape before 2.1.15 Home Directory Disclosure via BusyBox CWE-116 4.8 Medium2026-08-15
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD CWE-78 9.2 Critical2026-08-12
CVE-2026-73413 Shescape: Quadratic-time denial of service in flag-protection CWE-400 8.7 High2026-08-12
CVE-2026-73412 Shescape: Path disclosure on Unix with Zsh CWE-78 6.3 Medium2026-08-12
CVE-2026-73411 Shescape: Home-directory disclosure in assignment context on Unix with Dash CWE-116 6.3 Medium2026-08-12
CVE-2026-32094 Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash CWE-200 7.5AIHighAI2026-03-11
CVE-2025-30222 Shescape has potential environment variable exposure on Windows with CMD CWE-200 7.5AIHighAI2025-03-25
CVE-2023-40185 Shescape on Windows escaping may be bypassed in threaded context CWE-150 6.5 Medium2023-08-23
CVE-2023-35931 Shescape potential environment variable exposure on Windows with CMD CWE-526 3.1 Low2023-06-23
CVE-2022-25918 Regular Expression Denial of Service (ReDoS) 5.3 Medium2022-10-27
CVE-2022-36064 Shescape Inefficient Regular Expression Complexity vulnerability CWE-1333 5.9 Medium2022-09-06
CVE-2022-31179 Insufficient escaping of line feeds for CMD in shescape CWE-74 8.1 High2022-08-01
CVE-2022-31180 Insufficient escaping of whitespace in shescape CWE-74 9.8 Critical2022-08-01
CVE-2022-24725 Exposure of home directory through shescape on Unix with Bash CWE-200 6.2 Medium2022-03-03
CVE-2021-21384 Null characters not escaped in shescape CWE-88 6.3 Medium2021-03-18

All 15 known CVE vulnerabilities affecting shescape with full Chinese analysis, references, and POCs where available.