14 Total advisories
14 Vulnerabilities
0 Malware
Dependency scanning
Check whether shescape is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-73412
Shescape: Path disclosure on Unix with Zsh
UNKNOWN
CVE-2026-73414
Shescape: Shell injection via unescaped parentheses on Windows with CMD
UNKNOWN
CVE-2026-73413
Shescape: Quadratic-time denial of service in the flag-protection
UNKNOWN
CVE-2026-73411
Shescape: Home-directory disclosure in assignment context on Unix with Dash
UNKNOWN
CVE-2026-30916
Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains
MEDIUM 6.3
CVE-2021-21384
Null characters not escaped
UNKNOWN
CVE-2026-32094
Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash
UNKNOWN
CVE-2025-30222
Shescape has potential environment variable exposure on Windows with CMD
HIGH 8.6
CVE-2023-40185
Shescape on Windows escaping may be bypassed in threaded context
LOW 3.1
CVE-2023-35931
Shescape potential environment variable exposure on Windows with CMD
CRITICAL 9.8
CVE-2022-31180
Shescape vulnerable to insufficient escaping of whitespace
HIGH 8.1
CVE-2022-31179
Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD
HIGH 7.5
CVE-2022-25918
Inefficient Regular Expression Complexity in shescape
MEDIUM 5.5
CVE-2022-24725
Exposure of home directory through shescape on Unix with Bash
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes