Shescape Project maintains a specialized shell-escaping and command-injection prevention library that, despite its narrow product scope, serves a security-critical role in protecting applications that construct and execute shell commands. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around its core function: improper neutralization of special elements and argument delimiters, information exposure through environment variables, and regular expression complexity issues that can undermine the escaping guarantees the library is designed to provide. Defenders using this library should monitor disclosures closely, as flaws here directly impact the security posture of downstream applications; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shescape Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31180CRITICAL Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impac | Aug 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-31179CRITICAL Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (any A | Aug 1, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-25918HIGH The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure r | Oct 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-21384HIGH shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable agains | Mar 19, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-40185HIGH shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping | Aug 23, 2023 | 8.6 | 23 | NO | NO |
CVE-2026-32094MEDIUM Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications | Mar 11, 2026 | 6.5 | 22 | NO | NO |
CVE-2022-24725MEDIUM Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` o | Mar 3, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36064HIGH Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shell | Sep 6, 2022 | 7.5 | 19 | NO | NO |
CVE-2023-35931MEDIUM Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
| Jun 23, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shescape Project.
Media articles that mention a CVE ID that affects a product developed by Shescape Project — matched by CVE ID, not by vendor name.