CVE-2026-30916
Received
Received - Intake
Shell Escape Bypass in Shescape JavaScript Library Allows Data Exposure
Publication date: 2026-03-10
Last updated on: 2026-03-20
Assigner: GitHub, Inc.
Description
Description
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Further investigation determined that the software behavior described did not falls within the project's threat model. See https://github.com/github/advisory-database/pull/7206 for more information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ericcornelissen | shescape | 2.1.9 |
| ericcornelissen | shescape | to 2.1.9 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |