A version string used as a pattern
Input
v1.2.3 (build+42)Output
v1\.2\.3 \(build\+42\)Without escaping, the dots would match any character and the parentheses would create capture groups.
Around a dozen characters have special meaning in a regular expression. Escaping them with backslashes turns the text into a pattern that matches those characters literally, which is what you need when building a pattern from a string rather than writing one by hand.
The security reason to do this matters more than the convenience. Interpolating unescaped user input into a regex lets that input change the pattern's meaning, and a crafted value can produce a pattern that takes exponential time to run, a denial of service through a search box.
Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.
Input
v1.2.3 (build+42)Output
v1\.2\.3 \(build\+42\)Without escaping, the dots would match any character and the parentheses would create capture groups.
The details that decide whether a conversion is correct, and where information can be lost without any error being raised.