Shell Escape Vulnerability in Shescape Library for JavaScript
CVE-2026-73414
9.2CRITICAL
What is CVE-2026-73414?
The Shescape library for JavaScript contains a vulnerability that allows an attacker to exploit unescaped parentheses in command arguments when utilizing the escape or escapeAll APIs on Windows systems with cmd.exe. This flaw can lead to unauthorized command execution, as an attacker may break out of the intended command structure, injecting harmful shell syntax. This issue was addressed in versions 2.1.14 and 3.0.1 of the library.
Affected Version(s)
shescape < 2.1.14 < 2.1.14
shescape >= 3.0.0, < 3.0.1 < 3.0.0, 3.0.1
