← Back to CVE List

CVE-2023-40185

Published: 2023-08-23T21:15Z
Last Modified: 2024-11-21T08:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt