What is CVE-2026-73055?
The Shescape library versions prior to 2.1.15 incorrectly escape the tilde (~) character when used with the 'sh' shell configuration on Unix systems. This vulnerability affects the `escape` and `escapeAll` APIs in assignment contexts, potentially enabling command execution. Users should upgrade to Shescape 2.1.15 or 3.0.2 to mitigate the issue.
Azərbaycanca: Shescape kitabxanasının 2.1.15-dən əvvəlki versiyaları Unix sistemlərində `sh` shell konfiqurasiyası ilə işləyərkən tilde (~) simvolunu düzgün escape etmir. Bu zəiflik `escape` və `escapeAll` API-lərindən istifadə edərkən, xüsusilə təyinat kontekstlərində zərərli əmrlərin icrasına səbəb ola bilər. Shescape-i 2.1.15 və ya 3.0.2 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What software or component is affected by vulnerability CVE-2026-73055?
CVE-2026-73055 affects Shescape library versions prior to 2.1.15.
What mitigation is recommended for CVE-2026-73055 in the Shescape library?
Upgrading the Shescape library to version 2.1.15 or 3.0.2 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.