{"id":"CVE-2026-73414","summary":"Shescape: Shell injection via unescaped parentheses on Windows with CMD","details":"Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escapeAll APIs on Windows with shell set to cmd.exe, or with shell set to true when CMD is the default. An attacker-controlled argument can break out of a parenthesized CMD construct and inject shell syntax depending on the original command, resulting in arbitrary command execution. This issue is fixed in versions 2.1.14 and 3.0.1.","aliases":["GHSA-w4hw-qcx7-56pr"],"modified":"2026-09-11T03:30:34.805605841Z","published":"2026-08-12T19:42:55.520Z","database_specific":{"cwe_ids":["CWE-150","CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73414.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/releases/tag/v2.1.14"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/releases/tag/v3.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73414.json"},{"type":"ADVISORY","url":"https://github.com/ericcornelissen/shescape/security/advisories/GHSA-w4hw-qcx7-56pr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73414"},{"type":"FIX","url":"https://github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de"},{"type":"FIX","url":"https://github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f"},{"type":"FIX","url":"https://github.com/ericcornelissen/shescape/pull/2649"},{"type":"FIX","url":"https://github.com/ericcornelissen/shescape/pull/2651"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ericcornelissen/shescape","events":[{"introduced":"0"},{"introduced":"68b9e590b7527fd9dbde91c450055059423942f6"},{"fixed":"ae0faa7bd31331aec3f21c623ee69a50e6663454"},{"fixed":"37303332910d456bf07bbf942c3ed98be156f365"},{"fixed":"43d70b59d09bbe5c3fd02ef08b3a123e977ed9de"},{"fixed":"b4b34c394e7f9da2775bb75381066b9a228c425f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.1.14"},{"introduced":"3.0.0"},{"fixed":"3.0.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.1.13","v3.0.0","v2.1.12","v2.1.11","v2.1.10","v2.1.9","v2.1.8","v2.1.7","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.1.0","v2.0.2","v2.0.1","v2.0.0","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.7","v1.6.6","v1.6.5","v1.6.4","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.10","v1.5.9","v1.5.8","v1.5.7","v1.5.6","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.0","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.0","v0.4.1","v0.4.0","v0.3.1","v0.3.0","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73414.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}