VDB
Sign up
MEDIUM6.3

GHSA-f2rp-38vg-j3gh

Null characters not escaped

Quick fix

GHSA-f2rp-38vg-j3gh — shescape: upgrade to the fixed version with the command below.

npm install shescape@1.1.3

Details

### Impact

Anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a [null character](https://en.wikipedia.org/wiki/Null_character) into the payload. For example (on Windows):

```javascript const cp = require("child_process"); const shescape = require("shescape");

const nullChar = String.fromCharCode(0); const payload = "foo\" && ls -al ${nullChar} && echo \"bar"; console.log(cp.execSync(`echo ${shescape.quote(payload)}`)); // foototal 3 // drwxr-xr-x 1 owner XXXXXX 0 Mar 13 18:44 . // drwxr-xr-x 1 owner XXXXXX 0 Mar 13 00:09 .. // drwxr-xr-x 1 owner XXXXXX 0 Mar 13 18:42 folder // -rw-r--r-- 1 owner XXXXXX 0 Mar 13 18:42 file ```

### Patches

The problem has been patched in [v1.1.3](https://github.com/ericcornelissen/shescape/releases/tag/v1.1.3) which you can upgrade to now. No further changes are required.

### Workarounds

Alternatively, null characters can be stripped out manually using e.g. `arg.replace(/\u{0}/gu, "")`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/shescape
Introduced in: 0Fixed in: 1.1.3
Fixnpm install shescape@1.1.3

References