PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73055 ericcornelissen CVE debrief

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to 'sh' or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates. Affected systems require immediate attention to prevent potential exploitation. The vulnerability has a high impact on Unix-based systems, particularly those utilizing BusyBox. System administrators and developers should review their systems for potential exposure, verify Shescape versions, and apply patches or updates as necessary. Security teams should also monitor for suspicious activity and implement compensating controls where necessary.

Vendor
ericcornelissen
Product
shescape
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-26
Advisory published
2026-08-15
Advisory updated
2026-08-26

Who should care

Unix-based system administrators and developers using Shescape versions before 2.1.15 or 3.0.0 to 3.0.1, especially with BusyBox, should be aware of this vulnerability. They should review their systems for potential exposure, verify Shescape versions, and apply patches or updates as necessary. Security teams should also monitor for suspicious activity and implement compensating controls where necessary.

Technical summary

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to 'sh' or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates. Affected systems require immediate attention to prevent potential exploitation.

Defensive priority

High priority for Unix-based systems using Shescape versions before 2.1.15 or 3.0.0 to 3.0.1, especially with BusyBox.

Recommended defensive actions

  • Inventory and verify Shescape version, especially for Unix-based systems
  • Apply patches or updates to Shescape version 2.1.15 or 3.0.2
  • Implement compensating controls, such as input validation and sanitization
  • Monitor for suspicious activity and exception tracking
  • Review system configurations for potential exposure
  • Verify Shescape versions in use across the environment
  • Track exceptions and retest remediated assets

Evidence notes

Evidence from official sources indicates a critical vulnerability in Shescape, allowing disclosure of user home directory location and potential command operation alteration. Limited evidence exists on affected scope and vendor remediation. Defenders should verify Shescape versions, review system configurations, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73055 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73055

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73055 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73055

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.