Shell-quote Vulnerability in Node.js by LJHarb
CVE-2026-102422
What is CVE-2026-102422?
The shell-quote library's quote() function poses a security risk by improperly handling comment tokens within command strings. Specifically, when a { comment } token is included, it generates a line starting with #, which comments out subsequent input that follows it, including the opening quote of later string tokens. This behavior allows malicious input, such as line terminators in untrusted commands, to be executed unknowingly. As a result, commands like quote(['echo', 'ok', { comment: 'x' }, 'a id;#']) can inadvertently execute unintended code such as id within various shell environments. A fix has been implemented in version 1.11.0, preventing the inclusion of line terminators in tokens that follow comment tokens.
Affected Version(s)
shell-quote 1.8.4 < 1.11.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
