Shell-quote Vulnerability in Node.js by LJHarb
CVE-2026-102422

9.2CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102422?

The shell-quote library's quote() function poses a security risk by improperly handling comment tokens within command strings. Specifically, when a { comment } token is included, it generates a line starting with #, which comments out subsequent input that follows it, including the opening quote of later string tokens. This behavior allows malicious input, such as line terminators in untrusted commands, to be executed unknowingly. As a result, commands like quote(['echo', 'ok', { comment: 'x' }, 'a id;#']) can inadvertently execute unintended code such as id within various shell environments. A fix has been implemented in version 1.11.0, preventing the inclusion of line terminators in tokens that follow comment tokens.

Affected Version(s)

shell-quote 1.8.4 < 1.11.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eurico Nicacio (@euriconicacio)
Jordan Harband (@ljharb)
.