From aba57aea75f7a0a4d380273b2e91de36ef621b4e Mon Sep 17 00:00:00 2001 From: Antonis Loukis Date: Sun, 16 Aug 2026 17:10:10 +0300 Subject: [PATCH] Improve GHSA-jfpg-hfv5-2rf7 --- .../GHSA-jfpg-hfv5-2rf7.json | 72 ++++++++++++++++--- 1 file changed, 62 insertions(+), 10 deletions(-) diff --git a/advisories/unreviewed/2026/08/GHSA-jfpg-hfv5-2rf7/GHSA-jfpg-hfv5-2rf7.json b/advisories/unreviewed/2026/08/GHSA-jfpg-hfv5-2rf7/GHSA-jfpg-hfv5-2rf7.json index c931ce2a829..f5c87135d24 100644 --- a/advisories/unreviewed/2026/08/GHSA-jfpg-hfv5-2rf7/GHSA-jfpg-hfv5-2rf7.json +++ b/advisories/unreviewed/2026/08/GHSA-jfpg-hfv5-2rf7/GHSA-jfpg-hfv5-2rf7.json @@ -1,23 +1,54 @@ { "schema_version": "1.4.0", "id": "GHSA-jfpg-hfv5-2rf7", - "modified": "2026-08-16T00:31:28Z", + "modified": "2026-08-16T00:31:29Z", "published": "2026-08-16T00:31:28Z", "aliases": [ "CVE-2026-73055" ], - "details": "Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to \"sh\" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.", - "severity": [ + "summary": "Shescape: Home-directory disclosure in assignment context on Unix with BusyBox", + "details": "Shescape versions before 2.1.15, and versions 3.0.0 through 3.0.1, do not correctly escape tilde (`~`) characters in assignment contexts on Unix systems when `shell` is configured as `\"sh\"` (or `true`) and `/bin/sh` resolves to BusyBox.\n\nWhen the `escape()` or `escapeAll()` APIs are used with untrusted input in an assignment prefixed to a command, tilde expansion can expose the current user's home-directory path and may cause a command to operate on an unintended location.\n\nThe issue is fixed in Shescape 2.1.15 and 3.0.2.", + "severity": [], + "affected": [ { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + "package": { + "ecosystem": "npm", + "name": "shescape" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.15" + } + ] + } + ] }, { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "package": { + "ecosystem": "npm", + "name": "shescape" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.0.2" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "WEB", @@ -27,6 +58,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73055" }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/pull/2677" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/pull/2678" + }, { "type": "WEB", "url": "https://github.com/ericcornelissen/shescape/commit/7cba30594c16a21524706efe2f6c6c9d8923f411" @@ -35,6 +74,18 @@ "type": "WEB", "url": "https://github.com/ericcornelissen/shescape/commit/d86bf2ae22961c73458bddf70dd06adf9dadb36c" }, + { + "type": "PACKAGE", + "url": "https://github.com/ericcornelissen/shescape" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/releases/tag/v2.1.15" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/releases/tag/v3.0.2" + }, { "type": "WEB", "url": "https://www.vulncheck.com/advisories/shescape-before-home-directory-disclosure-via-busybox" @@ -42,9 +93,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-116" + "CWE-116", + "CWE-200" ], - "severity": "CRITICAL", + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2026-08-15T22:16:55Z"