CRITICAL 9.3 NVD

CVE-2026-73055

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicit

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.

References

Published: 2026-08-15 · Source: NVD · Feed updated: 2026-08-16
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-15 via NVD.

Risk Timeline

CVE Disclosed2026-08-15 · 0 days ago

Remediation Resources

vulnfeed aggregates 11804 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.