Aller au contenu

Fiche vulnérabilité

CVE-2023-40185 : faille élevée shescape project shescape (CVSS 8.6)

Description

shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.

En bref

Sévérité
Élevée (CVSS 8.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
23 août 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • shescape project shescape

Références

Rechercher une autre vulnérabilité dans la base CVE