CVE-2026-73055: Shescape before 2.1.15 Home Directory Disclosure via BusyBox
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shescapeto a version that resolves this vulnerability.Fixed in 2.1.15 - Upgrade
Upgrade
Shescapeto a version that resolves this vulnerability.Fixed in 3.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73055?
The severity of CVE-2026-73055 is medium with a score of 4.8.
How do I fix CVE-2026-73055?
To fix CVE-2026-73055, upgrade Shescape to version 2.1.15 or 3.0.2 or later.
What does CVE-2026-73055 affect?
CVE-2026-73055 affects Shescape versions before 2.1.15 and 3.0.0 before 3.0.2 on Unix systems using BusyBox.
What kind of vulnerability is CVE-2026-73055?
CVE-2026-73055 is a directory disclosure vulnerability related to improper escaping of tilde characters.
What is the potential impact of CVE-2026-73055?
The potential impact of CVE-2026-73055 includes unauthorized exposure of the home directory when using vulnerable versions of Shescape.