GHSA-3g7p-8qhx-mc8r
Shescape potential environment variable exposure on Windows with CMD
Quick fix
GHSA-3g7p-8qhx-mc8r — shescape: upgrade to the fixed version with the command below.
npm install shescape@1.7.1Details
### Impact
This impact users of Shescape:
1. On Windows using the Windows Command Prompt (i.e. `cmd.exe`), and 2. Using `quote`/`quoteAll` or `escape`/`escapeAll` with the `interpolation` option set to `true`.
An attacker may be able to get read-only access to environment variables. Example:
```javascript import * as cp from "node:child_process"; import * as shescape from "shescape";
// 1. Prerequisites const options = { shell: "cmd.exe", // Or shell: undefined, // Only if the default shell is CMD
// And interpolation: true, // Only applies to `escape` and `escapeAll` usage }
// 2. Attack (one of many) const payload = "%PATH%";
// 3. Usage let escapedPayload;
escapedPayload = shescape.quote(payload, options); // Or escapedPayload = shescape.quoteAll([payload], options); // Or escapedPayload = shescape.escape(payload, options); // Or escapedPayload = shescape.escapeAll([payload], options);
// And (example) const result = cp.execSync(`echo Hello ${escapedPayload}`, options);
// 4. Impact console.log(result.toString()); // Outputs "Hello" followed by the contents of the PATH environment variable ```
### Patches
This bug has been patched in [v1.7.1](https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1) which you can upgrade to now. No further changes are required.
### Workarounds
Alternatively, users can remove all instances of `%` from user input, either before or after using Shescape.
### References
- Shescape Pull request [#982](https://github.com/ericcornelissen/shescape/pull/982) - Shescape commit [`d0fce70`](https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac) - Shescape Release [v1.7.1](https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-35931[ADVISORY]
- https://github.com/ericcornelissen/shescape/pull/982[WEB]
- https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac[WEB]
- https://github.com/ericcornelissen/shescape[PACKAGE]
- https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1[WEB]