<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T17:23:09.670853+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-206146</id>
    <title>EUVD-2026-206146</title>
    <updated>2026-10-05T17:23:09.719454+00:00</updated>
    <content>EUVD-2026-206146</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-206146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-35931</id>
    <title>fkie_cve-2023-35931</title>
    <updated>2026-10-05T17:23:09.719488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-35931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3g7p-8qhx-mc8r</id>
    <title>GHSA-3g7p-8qhx-mc8r — Shescape potential environment variable exposure on Windows with CMD</title>
    <updated>2026-10-05T17:23:09.719519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: shescape</p>
<p>### Impact</p>
<p>This impact users of Shescape:</p>
<p>1. On Windows using the Windows Command Prompt (i.e. `cmd.exe`), and
2. Using `quote`/`quoteAll` or `escape`/`escapeAll` with the `interpolation` option set to `true`.</p>
<p>An attacker may be able to get read-only access to environment variables. Example:</p>
<p>```javascript
import * as cp from "node:child_process";
import * as shescape from "shescape";</p>
<p>// 1. Prerequisites
const options = {
    shell: "cmd.exe",
    // Or
    shell: undefined, // Only if the default shell is CMD</p>
<p>// And
    interpolation: true, // Only applies to `escape` and `escapeAll` usage
}</p>
<p>// 2. Attack (one of many)
const payload = "%PATH%";</p>
<p>// 3. Usage
let escapedPayload;</p>
<p>escapedPayload = shescape.quote(payload, options);
// Or
escapedPayload = shescape.quoteAll([payload], options);
// Or
escapedPayload = shescape.escape(payload, options);
// Or
escapedPayload = shescape.escapeAll([payload], options);</p>
<p>// And (example)
const result = cp.execSync(`echo Hello ${escapedPayload}`, options);</p>
<p>// 4. Impact
console.log(result.toString());
// Outputs "Hello" followed by the contents of the PATH environment variable
```</p>
<p>### Patches</p>
<p>This bug has been patched in [v1.7.1](https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1) which you can upgrade to now. No further changes are required.</p>
<p>### Workarounds</p>
<p>Alternatively, users can remove all instances of `%` from user input, either before or after using Shescape.</p>
<p>### References</p>
<p>- Shescape Pull request [#982]…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3g7p-8qhx-mc8r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-35931</id>
    <title>gsd-2023-35931</title>
    <updated>2026-10-05T17:23:09.719571+00:00</updated>
    <content>gsd-2023-35931</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-35931"/>
  </entry>
</feed>
