Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Shescape Project

First CVE: Mar 19, 2021Active for: 5 yearsTotal CVEs: 9

Shescape Project maintains a specialized shell-escaping and command-injection prevention library that, despite its narrow product scope, serves a security-critical role in protecting applications that construct and execute shell commands. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around its core function: improper neutralization of special elements and argument delimiters, information exposure through environment variables, and regular expression complexity issues that can undermine the escaping guarantees the library is designed to provide. Defenders using this library should monitor disclosures closely, as flaws here directly impact the security posture of downstream applications; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Shescape Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 19, 2021
5 years ago
Most Recent CVE
Mar 11, 2026
136 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-31180CRITICAL
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impac
Aug 1, 20229.831NONO
CVE-2022-31179CRITICAL
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (any A
Aug 1, 20229.829NONO
CVE-2022-25918HIGH
The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure r
Oct 27, 20227.524NONO
CVE-2021-21384HIGH
shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable agains
Mar 19, 20217.824NONO
CVE-2023-40185HIGH
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping
Aug 23, 20238.623NONO
CVE-2026-32094MEDIUM
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications
Mar 11, 20266.522NONO
CVE-2022-24725MEDIUM
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` o
Mar 3, 20225.520NONO
CVE-2022-36064HIGH
Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shell
Sep 6, 20227.519NONO
CVE-2023-35931MEDIUM
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
Jun 23, 20234.315NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
44%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Shescape Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Shescape Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Shescape Project's Products

View all 2 CNAs →

Top CWEs