LOWVulnerability

CVE-2026-73413

Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments when flagProtection is enabled, which is the default, making processing quadratic in input size across the escape, escapeAll, quote, and quoteAll APIs. An attacker who can supply a large untrusted input containing many flag fragments can consume CPU and cause denial of service. This issue is fixed in versions 2.1.14 and 3.0.1.

Properties

epss_score
0.00336
cve_id
CVE-2026-73413
published_at
2026-08-12T20:17:56.350
last_modified
2026-09-09T21:02:22.660
epss_percentile
0.26549

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Inefficient Algorithmic Complexity

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73413 — Ninja Signal Threat Intelligence | Ninja Signal