---
id: CVE-2026-73413
title: Shescape is a simple shell escape library for JavaScript
summary: >-
  Shescape is a simple shell escape library for JavaScript. From 2.1.11 until
  2.1.14 and 3.0.1, the flag-protection loop in compose in
  src/internal/compose.js repeatedly joins and slices flag fragments when
  flagProtection is enabled, which…
severity: none
cwe:
  - CWE-400
  - CWE-407
published: '2026-08-12'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:02:22.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73413'
references:
  - url: >-
      https://github.com/ericcornelissen/shescape/commit/43d70b59d09bbe5c3fd02ef08b3a123e977ed9de
    label: security-advisories@github.com
  - url: >-
      https://github.com/ericcornelissen/shescape/commit/b4b34c394e7f9da2775bb75381066b9a228c425f
    label: security-advisories@github.com
  - url: 'https://github.com/ericcornelissen/shescape/pull/2649'
    label: security-advisories@github.com
  - url: 'https://github.com/ericcornelissen/shescape/pull/2651'
    label: security-advisories@github.com
  - url: 'https://github.com/ericcornelissen/shescape/releases/tag/v2.1.14'
    label: security-advisories@github.com
  - url: 'https://github.com/ericcornelissen/shescape/releases/tag/v3.0.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/ericcornelissen/shescape/security/advisories/GHSA-gm3r-q2wp-hw87
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0059
epssPercentile: 0.45924
ingestedAt: '2026-09-09T21:22:45.532Z'
---

## Overview

Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments when flagProtection is enabled, which is the default, making processing quadratic in input size across the escape, escapeAll, quote, and quoteAll APIs. An attacker who can supply a large untrusted input containing many flag fragments can consume CPU and cause denial of service. This issue is fixed in versions 2.1.14 and 3.0.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
