Description
The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7081 | The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function. |
Github GHSA |
GHSA-cr84-xvw4-qx3c | Inefficient Regular Expression Complexity in shescape |
References
History
Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-05-05T18:24:44.572Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25918
Updated: 2024-08-03T04:49:44.464Z
Status : Modified
Published: 2022-10-27T10:15:10.637
Modified: 2025-05-05T19:15:53.727
Link: CVE-2022-25918
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA