Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 15 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates. | |
| Title | Shescape before 2.1.15 Home Directory Disclosure via BusyBox | |
| First Time appeared |
Shescape Project
Shescape Project shescape |
|
| Weaknesses | CWE-116 | |
| CPEs | cpe:2.3:a:shescape_project:shescape:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Shescape Project
Shescape Project shescape |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-15T21:44:54.677Z
Reserved: 2026-08-10T19:10:18.101Z
Link: CVE-2026-73055
No data.
Status : Received
Published: 2026-08-15T22:16:55.427
Modified: 2026-08-15T22:16:55.427
Link: CVE-2026-73055
No data.
OpenCVE Enrichment
No data.