CVE-2026-73414 | ericcornelissen Shescape up to 2.1.13/3.0.0 src/internal/win/cmd.js getEscapeFunction os command injection
A vulnerability described as critical has been identified in ericcornelissen Shescape up to 2.1.13/3.0.0. Impacted is the function getEscapeFunction of the file src/internal/win/cmd.js. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-73414. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More