Fiche vulnérabilité
CVE-2023-40185 : faille élevée shescape project shescape (CVSS 8.6)
Description
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.
En bref
- Sévérité
- Élevée (CVSS 8.6)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 23 août 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- shescape project shescape