Back to Database
Status published
Low
CVE-2023-35931
Shescape potential environment variable exposure on Windows with CMD
Vulnerability Description
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-35931
Credits & Attribution
No credits recorded in the NVD database.
References
More from ericcornelissen
View All →CVE-2025-30222
Shescape has potential environment variable exposure on Windows with CMD
Low
2.1
CVE-2023-40185
Shescape on Windows escaping may be bypassed in threaded context
Medium
6.5
CVE-2022-36064
Shescape Inefficient Regular Expression Complexity vulnerability
Medium
5.9
CVE-2022-31180
Insufficient escaping of whitespace in shescape
Critical
9.8
CVE-2022-31179
Insufficient escaping of line feeds for CMD in shescape
High
8.1
Affected Vendor
ericcornelissen
View all reports →Affected Software
shescape
Vulnerable Versions:
< 1.7.1
Timeline
Official Publish:
June 23rd, 2023
Last Modified:
December 5th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.