| Name | CVE-2026-102422 |
| Description | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6548-1 |
| Debian Bugs | 1149713 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| node-shell-quote (PTS) | bookworm, bookworm (security) | 1.7.4+~1.7.1-1+deb12u1 | vulnerable |
| trixie | 1.7.4+~1.7.1-1+deb13u1 | vulnerable | |
| trixie (security) | 1.7.4+~1.7.1-1+deb13u2 | fixed | |
| forky, sid | 1.12.0-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| node-shell-quote | source | trixie | 1.7.4+~1.7.1-1+deb13u2 | DSA-6548-1 | ||
| node-shell-quote | source | (unstable) | 1.12.0-1 | 1149713 |
https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv
Fixed by: https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc (v1.11.0)