The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: snyk
Published: 2022-10-27T05:05:09.944Z
Updated: 2025-05-05T18:24:44.572Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25918
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T04:49:44.464Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-10-27T10:15:10.637
Modified: 2025-05-05T19:15:53.727
Link: CVE-2022-25918
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow