{"id":"GHSA-jjc5-fp7p-6f8w","summary":"Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD","details":"### Impact\n\nThis impacts users that use Shescape (any API function) to escape arguments for **cmd.exe** on **Windows**. An attacker can omit all arguments following their input by including a line feed character (`'\\n'`) in the payload. Example:\n\n```javascript\nimport cp from \"node:child_process\";\nimport * as shescape from \"shescape\";\n\n// 1. Prerequisites\nconst options = {\n  shell: \"cmd.exe\",\n};\n\n// 2. Attack\nconst payload = \"attacker\\n\";\n\n// 3. Usage\nlet escapedPayload;\nescapedPayload = shescape.escape(payload, options);\n// Or\nescapedPayload = shescape.escapeAll([payload], options)[0];\n// Or\nescapedPayload = shescape.quote(payload, options);\n// Or\nescapedPayload = shescape.quoteAll([payload], options)[0];\n\ncp.execSync(`echo Hello ${escapedPayload}! How are you doing?`, options);\n// Outputs:  \"Hello attacker\"\n```\n\n\u003e **Note**: `execSync` is just illustrative here, all of `exec`, `execFile`, `execFileSync`, `fork`, `spawn`, and `spawnSync` can be attacked using a line feed character if CMD is the shell being used.\n\n### Patches\n\nThis bug has been patched in [v1.5.8] which you can upgrade to now. No further changes are required.\n\n### Workarounds\n\nAlternatively, line feed characters (`'\\n'`) can be stripped out manually or the user input can be made the last argument (this only limits the impact).\n\n### References\n\n- https://github.com/ericcornelissen/shescape/pull/332\n- https://github.com/ericcornelissen/shescape/releases/tag/v1.5.8\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Comment on https://github.com/ericcornelissen/shescape/pull/332\n- Open an issue at https://github.com/ericcornelissen/shescape/issues (_New issue_ \u003e _Question_ \u003e _Get started_)\n\n[v1.5.8]: https://github.com/ericcornelissen/shescape/releases/tag/v1.5.8\n","aliases":["CVE-2022-31179"],"modified":"2023-11-08T04:09:28.955315Z","published":"2022-07-15T21:39:14Z","database_specific":{"cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-15T21:39:14Z","nvd_published_at":"2022-08-01T20:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/security/advisories/GHSA-jjc5-fp7p-6f8w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31179"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/pull/332"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/commit/aceea7358f7222984e21260381ebc5ec4543b76f"},{"type":"PACKAGE","url":"https://github.com/ericcornelissen/shescape"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/releases/tag/v1.5.8"}],"affected":[{"package":{"name":"shescape","ecosystem":"npm","purl":"pkg:npm/shescape"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-jjc5-fp7p-6f8w/GHSA-jjc5-fp7p-6f8w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H"}]}