{"schema_version":1,"title":"shescape (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in shescape (npm): 0 in the last 7 days and 8 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73413, was published on 24 July 2026.","url":"https://junglewise.ai/threats/technologies/shescape","json_url":"https://junglewise.ai/threats/technologies/shescape.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/shescape","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":18,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":8,"last_365_days":10},"latest":[{"cve":"CVE-2026-73413","cvss":4,"epss":0.0059,"slug":"cve-2026-73413-shescape-quadratic-time-denial-of-service-in-flag-protection","title":"Shescape quadratic-time denial of service in flag-protection","severity":"medium","exploited":false,"published_at":"2026-07-24T22:35:08+00:00","url":"https://junglewise.ai/threats/cve-2026-73413-shescape-quadratic-time-denial-of-service-in-flag-protection"},{"cvss":8.7,"slug":"shescape-quadratic-time-denial-of-service-in-flag-protection-d5f3788b","title":"Shescape quadratic-time denial of service in flag-protection","severity":"high","exploited":false,"published_at":"2026-07-24T22:35:08+00:00","url":"https://junglewise.ai/threats/shescape-quadratic-time-denial-of-service-in-flag-protection-d5f3788b"},{"cve":"CVE-2026-73411","cvss":4,"epss":0.0059,"slug":"cve-2026-73411-shescape-home-directory-disclosure-in-dash-shell-assignment","title":"Shescape home-directory disclosure in Dash shell assignment","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:39+00:00","url":"https://junglewise.ai/threats/cve-2026-73411-shescape-home-directory-disclosure-in-dash-shell-assignment"},{"cvss":6.3,"slug":"shescape-home-directory-disclosure-in-assignment-context-with-dash-e9c8b06d","title":"Shescape home-directory disclosure in assignment context with Dash shell","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:39+00:00","url":"https://junglewise.ai/threats/shescape-home-directory-disclosure-in-assignment-context-with-dash-e9c8b06d"},{"cvss":9.2,"slug":"shescape-shell-injection-via-unescaped-parentheses-in-cmd-on-windows-7d0d0053","title":"Shescape shell injection via unescaped parentheses in CMD on Windows","severity":"critical","exploited":false,"published_at":"2026-07-24T22:34:23+00:00","url":"https://junglewise.ai/threats/shescape-shell-injection-via-unescaped-parentheses-in-cmd-on-windows-7d0d0053"},{"cve":"CVE-2026-73414","cvss":4,"epss":0.0089,"slug":"cve-2026-73414-shescape-shell-injection-via-unescaped-parentheses-on-windows-cmd","title":"Shescape shell injection via unescaped parentheses on Windows CMD","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:23+00:00","url":"https://junglewise.ai/threats/cve-2026-73414-shescape-shell-injection-via-unescaped-parentheses-on-windows-cmd"},{"cve":"CVE-2026-73412","cvss":4,"epss":0.0061,"slug":"cve-2026-73412-shescape-path-disclosure-on-unix-with-zsh","title":"Shescape path disclosure on Unix with Zsh","severity":"medium","exploited":false,"published_at":"2026-07-24T22:33:38+00:00","url":"https://junglewise.ai/threats/cve-2026-73412-shescape-path-disclosure-on-unix-with-zsh"},{"cvss":6.3,"slug":"shescape-path-disclosure-in-zsh-shell-escaping-ad9e7b53","title":"Shescape path disclosure in Zsh shell escaping","severity":"medium","exploited":false,"published_at":"2026-07-24T22:33:38+00:00","url":"https://junglewise.ai/threats/shescape-path-disclosure-in-zsh-shell-escaping-ad9e7b53"},{"cve":"CVE-2026-32094","cvss":4,"epss":0.003,"slug":"cve-2026-32094-shescape-escape-bracket-glob-expansion-bypass-on-bash-busybox-and","title":"Shescape escape() bracket glob expansion bypass on Bash, BusyBox, and Dash","severity":"medium","exploited":false,"published_at":"2026-03-11T19:53:53+00:00","url":"https://junglewise.ai/threats/cve-2026-32094-shescape-escape-bracket-glob-expansion-bypass-on-bash-busybox-and"},{"cve":"CVE-2026-30916","cvss":4,"slug":"cve-2026-30916-shescape-shell-misidentification-via-symlink-chains","title":"Shescape shell misidentification via symlink chains","severity":"medium","exploited":false,"published_at":"2026-03-07T02:31:58+00:00","url":"https://junglewise.ai/threats/cve-2026-30916-shescape-shell-misidentification-via-symlink-chains"},{"cve":"CVE-2025-30222","cvss":4,"epss":0.0019,"slug":"cve-2025-30222-shescape-environment-variable-exposure-on-windows-with-cmd","title":"Shescape environment variable exposure on Windows with CMD","severity":"medium","exploited":false,"published_at":"2025-03-26T14:54:22+00:00","url":"https://junglewise.ai/threats/cve-2025-30222-shescape-environment-variable-exposure-on-windows-with-cmd"},{"cve":"CVE-2023-40185","cvss":3.1,"epss":0.0068,"slug":"cve-2023-40185-shescape-shell-escaping-bypass-in-threaded-context-on-windows","title":"Shescape shell escaping bypass in threaded context on Windows","severity":"low","exploited":false,"published_at":"2023-08-22T18:00:04+00:00","url":"https://junglewise.ai/threats/cve-2023-40185-shescape-shell-escaping-bypass-in-threaded-context-on-windows"},{"cve":"CVE-2023-35931","cvss":3.1,"slug":"cve-2023-35931-ericcornelissen-shescape-environment-variable-exposure-in-cmd","title":"ericcornelissen shescape environment variable exposure in CMD","severity":"low","exploited":false,"published_at":"2023-06-22T20:01:39+00:00","url":"https://junglewise.ai/threats/cve-2023-35931-ericcornelissen-shescape-environment-variable-exposure-in-cmd"},{"cve":"CVE-2022-25918","cvss":3.1,"epss":0.0133,"slug":"cve-2022-25918-shescape-inefficient-regex-complexity","title":"shescape inefficient regex complexity","severity":"low","exploited":false,"published_at":"2022-10-25T22:27:32+00:00","url":"https://junglewise.ai/threats/cve-2022-25918-shescape-inefficient-regex-complexity"},{"cve":"CVE-2022-31180","cvss":3.1,"epss":0.019,"slug":"cve-2022-31180-shescape-insufficient-escaping-of-whitespace-in-interpolation","title":"Shescape insufficient escaping of whitespace in interpolation mode","severity":"low","exploited":false,"published_at":"2022-07-15T21:46:08+00:00","url":"https://junglewise.ai/threats/cve-2022-31180-shescape-insufficient-escaping-of-whitespace-in-interpolation"},{"cve":"CVE-2022-31179","cvss":3.1,"epss":0.0135,"slug":"cve-2022-31179-shescape-insufficient-escaping-of-line-feeds-in-cmd","title":"Shescape insufficient escaping of line feeds in CMD","severity":"low","exploited":false,"published_at":"2022-07-15T21:39:14+00:00","url":"https://junglewise.ai/threats/cve-2022-31179-shescape-insufficient-escaping-of-line-feeds-in-cmd"},{"cve":"CVE-2022-24725","cvss":3.1,"epss":0.005,"slug":"cve-2022-24725-shescape-home-directory-exposure-in-bash-with-interpolation","title":"shescape home directory exposure in Bash with interpolation","severity":"low","exploited":false,"published_at":"2022-03-03T19:26:11+00:00","url":"https://junglewise.ai/threats/cve-2022-24725-shescape-home-directory-exposure-in-bash-with-interpolation"},{"cve":"CVE-2021-21384","cvss":3.1,"epss":0.0058,"slug":"cve-2021-21384-shescape-null-character-escape-bypass-in-shell-quoting","title":"Shescape null character escape bypass in shell quoting","severity":"low","exploited":false,"published_at":"2021-03-18T23:47:56+00:00","url":"https://junglewise.ai/threats/cve-2021-21384-shescape-null-character-escape-bypass-in-shell-quoting"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"}],"technology":{"hub":true,"name":"shescape (npm)","slug":"shescape","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://www.npmjs.com/package/shescape","repo_url":"https://github.com/ericcornelissen/shescape","description":"A library for escaping shell commands to prevent command injection vulnerabilities.","url":"https://junglewise.ai/threats/technologies/shescape"},"most_severe":[{"cvss":9.2,"slug":"shescape-shell-injection-via-unescaped-parentheses-in-cmd-on-windows-7d0d0053","title":"Shescape shell injection via unescaped parentheses in CMD on Windows","severity":"critical","exploited":false,"published_at":"2026-07-24T22:34:23+00:00","url":"https://junglewise.ai/threats/shescape-shell-injection-via-unescaped-parentheses-in-cmd-on-windows-7d0d0053"},{"cvss":8.7,"slug":"shescape-quadratic-time-denial-of-service-in-flag-protection-d5f3788b","title":"Shescape quadratic-time denial of service in flag-protection","severity":"high","exploited":false,"published_at":"2026-07-24T22:35:08+00:00","url":"https://junglewise.ai/threats/shescape-quadratic-time-denial-of-service-in-flag-protection-d5f3788b"},{"cvss":6.3,"slug":"shescape-home-directory-disclosure-in-assignment-context-with-dash-e9c8b06d","title":"Shescape home-directory disclosure in assignment context with Dash shell","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:39+00:00","url":"https://junglewise.ai/threats/shescape-home-directory-disclosure-in-assignment-context-with-dash-e9c8b06d"},{"cvss":6.3,"slug":"shescape-path-disclosure-in-zsh-shell-escaping-ad9e7b53","title":"Shescape path disclosure in Zsh shell escaping","severity":"medium","exploited":false,"published_at":"2026-07-24T22:33:38+00:00","url":"https://junglewise.ai/threats/shescape-path-disclosure-in-zsh-shell-escaping-ad9e7b53"},{"cve":"CVE-2026-73414","cvss":4,"epss":0.0089,"slug":"cve-2026-73414-shescape-shell-injection-via-unescaped-parentheses-on-windows-cmd","title":"Shescape shell injection via unescaped parentheses on Windows CMD","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:23+00:00","url":"https://junglewise.ai/threats/cve-2026-73414-shescape-shell-injection-via-unescaped-parentheses-on-windows-cmd"},{"cve":"CVE-2026-73412","cvss":4,"epss":0.0061,"slug":"cve-2026-73412-shescape-path-disclosure-on-unix-with-zsh","title":"Shescape path disclosure on Unix with Zsh","severity":"medium","exploited":false,"published_at":"2026-07-24T22:33:38+00:00","url":"https://junglewise.ai/threats/cve-2026-73412-shescape-path-disclosure-on-unix-with-zsh"},{"cve":"CVE-2026-73413","cvss":4,"epss":0.0059,"slug":"cve-2026-73413-shescape-quadratic-time-denial-of-service-in-flag-protection","title":"Shescape quadratic-time denial of service in flag-protection","severity":"medium","exploited":false,"published_at":"2026-07-24T22:35:08+00:00","url":"https://junglewise.ai/threats/cve-2026-73413-shescape-quadratic-time-denial-of-service-in-flag-protection"},{"cve":"CVE-2026-73411","cvss":4,"epss":0.0059,"slug":"cve-2026-73411-shescape-home-directory-disclosure-in-dash-shell-assignment","title":"Shescape home-directory disclosure in Dash shell assignment","severity":"medium","exploited":false,"published_at":"2026-07-24T22:34:39+00:00","url":"https://junglewise.ai/threats/cve-2026-73411-shescape-home-directory-disclosure-in-dash-shell-assignment"},{"cve":"CVE-2026-32094","cvss":4,"epss":0.003,"slug":"cve-2026-32094-shescape-escape-bracket-glob-expansion-bypass-on-bash-busybox-and","title":"Shescape escape() bracket glob expansion bypass on Bash, BusyBox, and Dash","severity":"medium","exploited":false,"published_at":"2026-03-11T19:53:53+00:00","url":"https://junglewise.ai/threats/cve-2026-32094-shescape-escape-bracket-glob-expansion-bypass-on-bash-busybox-and"},{"cve":"CVE-2025-30222","cvss":4,"epss":0.0019,"slug":"cve-2025-30222-shescape-environment-variable-exposure-on-windows-with-cmd","title":"Shescape environment variable exposure on Windows with CMD","severity":"medium","exploited":false,"published_at":"2025-03-26T14:54:22+00:00","url":"https://junglewise.ai/threats/cve-2025-30222-shescape-environment-variable-exposure-on-windows-with-cmd"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}