CVE-2023-40185
The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-150
- Affected
- shescape project/shescape
- Source
- security-advisories@github.com
References
- https://github.com/ericcornelissen/shescape/commit/0b976dab645abf45ffd85e74a8c6e51ee2f42d63Patch
- https://github.com/ericcornelissen/shescape/pull/1142Patch
- https://github.com/ericcornelissen/shescape/releases/tag/v1.7.4Release Notes
- https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j55r-787p-m549Exploit, Patch, Vendor Advisory
- https://github.com/ericcornelissen/shescape/commit/0b976dab645abf45ffd85e74a8c6e51ee2f42d63Patch
- https://github.com/ericcornelissen/shescape/pull/1142Patch
- https://github.com/ericcornelissen/shescape/releases/tag/v1.7.4Release Notes
- https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j55r-787p-m549Exploit, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.