GHSA-446w-rrm4-r47f

    Dashboard / Vulnerabilities / GHSA-446w-rrm4-r47f

    GHSA-446w-rrm4-r47f

    Published: 3 Mar 2022Last Modified: 8 Nov 2023

    Summary: Exposure of home directory through shescape on Unix with Bash

    Details: ### Impact The issue allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`. Other tested shells, Dash and Zsh, are not affected. ```javascript const cp = require("child_process"); const shescape = require("shescape"); const payload = "home_directory=~"; const options = { interpolation: true }; console.log(cp.execSync(`echo ${shescape.escape(payload, options)}`)); // home_directory=/home/user ``` Depending on how the output of _shescape_ is used, directory traversal may be possible in the application using _shescape_. ### Patches The issue was patched in `v1.5.1`. ### Workarounds Manually escape all instances of the tilde character (`~`) using `arg.replace(/~/g, "\\~")`. ### References See GitHub issue https://github.com/ericcornelissen/shescape/issues/169.

    Affected packages

    Package

    Name: shescape

    Purl: pkg:npm/shescape

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.4.0
    Fixed -1.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-446w-rrm4-r47f | CVE-DB