CVE-2026-102422 Details
Description
shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator.
A vulnerability in the 'shell-quote' package, specifically in versions 1.8.4 prior to 1.11.0, allows for command injection through the 'quote()' function. The issue arises because the function improperly handles comment tokens, which are indicated by a '{ comment }' object. When a line terminator is present in a string token following a comment token, the comment is terminated, and the remainder of the string is processed as shell input. This behavior can be exploited to execute arbitrary commands in various shell environments, including 'sh', 'bash', 'dash', 'ksh', and 'zsh'. The vulnerability is particularly concerning when 'parse()' output, which can include comment tokens, is combined with untrusted strings, as this can lead to unintended command execution.
Users can upgrade to 'shell-quote' version 1.11.0 or later, where this vulnerability has been fixed. The updated 'quote()' function now throws a TypeError when a string after a '{ comment }' token contains a line terminator.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ljharb/shell-quote | harborist | Source CodeVendor |
| https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc | harborist | Source CodeVendor |
| https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv | harborist | AdvisoryRemedyVendor |
| https://www.npmjs.com/package/shell-quote | harborist | Content WallVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | harborist |
Affected Products
| Product | Versions |
|---|---|
| ljharb shell-quote | >= 1.8.4, < 1.11.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | harborist |
Volerion