CVE-2021-21384
MEDIUMshescape <1.1.3 - Code Injection
Title source: llmDescription
shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The problem has been patched in version 1.1.3. No further changes are required.
Scores
CVSS v3
6.3
EPSS
0.0016
EPSS Percentile
37.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N
Classification
CWE
CWE-88
Status
published
Affected Products (2)
shescape_project/shescape
< 1.1.3
npm/shescape
< 1.1.3npm
Timeline
Published
Mar 19, 2021
Tracked Since
Feb 18, 2026