Source: node-shell-quote
Version: 1.10.0-1
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for node-shell-quote.

CVE-2026-102422[0]:
| shell-quote's `quote()` function emits a `{ comment }` token as `#`
| followed by its text, which comments out the rest of the shell line,
| including the opening quote of any later string token. A line
| terminator (\n, \r, U+2028, U+2029) in that later string therefore
| ends the comment, and the rest of the string is parsed as shell
| input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs
| `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token
| for a `#` in the middle of a word (for example
| `http://example.com/#frag`), so callers that combine `parse()`
| output with another untrusted string, such as
| `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected.
| The fix for CVE-2026-9277 rejected line terminators in the comment's
| own text, but not in the tokens after it. Fixed in 1.11.0: `quote()`
| throws a `TypeError` when a string after a `{ comment }` token
| contains a line terminator.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102422
    https://www.cve.org/CVERecord?id=CVE-2026-102422
[1] 
https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv
[2] 
https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to