PT-2025-12834 · Shescape · Shescape

Published

2025-03-25

·

Updated

2025-03-26

·

CVE-2025-30222

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Shescape versions 1.7.2 through 2.1.1
Description The issue affects users of Shescape on Windows who explicitly configure shell: 'cmd.exe' or shell: true using any of quote/quoteAll/escape/escapeAll. An attacker may be able to get read-only access to environment variables.
Recommendations For versions 1.7.2 through 2.1.1, upgrade to v2.1.2 or later. For those using v1 of Shescape, follow the migration guide to upgrade to v2. As a temporary workaround, remove all instances of % from user input before using Shescape.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30222
GHSA-66PP-5P9W-Q87J

Affected Products

Shescape