The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7081 | The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function. |
Github GHSA |
GHSA-cr84-xvw4-qx3c | Inefficient Regular Expression Complexity in shescape |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-05-05T18:24:44.572Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25918
Updated: 2024-08-03T04:49:44.464Z
Status : Modified
Published: 2022-10-27T10:15:10.637
Modified: 2025-05-05T19:15:53.727
Link: CVE-2022-25918
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA