The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: snyk
Published: 2022-10-27T05:05:09.944Z
Updated: 2025-05-05T18:24:44.572Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25918

Updated: 2024-08-03T04:49:44.464Z

Status : Modified
Published: 2022-10-27T10:15:10.637
Modified: 2025-05-05T19:15:53.727
Link: CVE-2022-25918

No data.