Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via the getEscapeFunction logic in src/internal/unix/busybox.js. An attacker can reveal the user's home directory and alter how a command interprets an assignment-prefixed value by supplying input such as :~ or a=~ to escape or escapeAll when Unix shell escaping targets BusyBox sh. On affected Unix systems where shell is set to "sh" or true and /bin/sh points to BusyBox, the escaped tilde is expanded in assignment contexts instead of being treated as data, causing commands like V=...; echo $V to print : followed by the home path.
Remediation
Upgrade shescape to version 2.1.15, 3.0.2 or higher.