Skip to content

[GHSA-jfpg-hfv5-2rf7] Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to... - #9136

Open
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9136from
antonisloukis-GHSA-jfpg-hfv5-2rf7
Open

[GHSA-jfpg-hfv5-2rf7] Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to...#9136
antonisloukis wants to merge 1 commit into
antonisloukis/advisory-improvement-9136from
antonisloukis-GHSA-jfpg-hfv5-2rf7

Conversation

@antonisloukis

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • CWEs
  • Description
  • References
  • Severity
  • Source code location
  • Summary

Comments
The current unreviewed advisory is missing package and source-code metadata.

The upstream Shescape security advisory GHSA-j44h-fqhh-fh28 identifies the affected package as shescape in the npm ecosystem, with affected version ranges < 2.1.15 and >= 3.0.0, < 3.0.2, and fixes released in versions 2.1.15 and 3.0.2.

The upstream advisory identifies the vulnerability as low severity and associates it with CWE-116 and CWE-200.

This suggestion aligns the GitHub Advisory Database entry with the upstream maintainer advisory and adds the missing package, source repository, affected/fixed versions, references, and weakness information.

@github-actions
github-actions Bot changed the base branch from main to antonisloukis/advisory-improvement-9136 August 16, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant