ZeroHour

CVE-2022-25918

PoC
CVSS 3.1
7.5 high
EPSS
1%p70
Published
()
Modified
Description

The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

Vendors
shescape project
Products
shescape
Weakness
CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.