{"id":"CVE-2026-32094","aliases":["GHSA-9jfh-9xrq-4vwm"],"url":"https://o3.security/vulnerability/CVE-2026-32094","summary":"Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash","details":"Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications that interpolate the return value directly into a shell command string can cause an attacker-controlled value like secret[12] to expand into multiple filesystem matches instead of a single literal argument, turning one argument into multiple trusted-pathname matches. This vulnerability is fixed in 2.1.10.","published":"2026-03-11T19:50:10.617Z","modified":"2026-08-12T03:51:25.118238643Z","cvss":null,"epss":{"score":0.00214,"percentile":0.11597,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"shescape","fixedVersion":"2.1.10"}],"fix":{"url":"https://github.com/ericcornelissen/shescape/commit/6add105c6f6b508662bb5ae3b3bdd4c9bcebf37a","label":"ericcornelissen/shescape@6add105"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32094.json"},{"type":"ADVISORY","url":"https://github.com/ericcornelissen/shescape/security/advisories/GHSA-9jfh-9xrq-4vwm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32094"},{"type":"FIX","url":"https://github.com/ericcornelissen/shescape/commit/6add105c6f6b508662bb5ae3b3bdd4c9bcebf37a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.118238643Z"}}