Your message dated Sat, 03 Oct 2026 06:04:46 +0000
with message-id <[email protected]>
and subject line Bug#1149713: fixed in node-shell-quote 1.12.0-1
has caused the Debian Bug report #1149713,
regarding node-shell-quote: CVE-2026-102422
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1149713: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149713
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-shell-quote
Version: 1.10.0-1
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for node-shell-quote.

CVE-2026-102422[0]:
| shell-quote's `quote()` function emits a `{ comment }` token as `#`
| followed by its text, which comments out the rest of the shell line,
| including the opening quote of any later string token. A line
| terminator (\n, \r, U+2028, U+2029) in that later string therefore
| ends the comment, and the rest of the string is parsed as shell
| input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs
| `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token
| for a `#` in the middle of a word (for example
| `http://example.com/#frag`), so callers that combine `parse()`
| output with another untrusted string, such as
| `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected.
| The fix for CVE-2026-9277 rejected line terminators in the comment's
| own text, but not in the tokens after it. Fixed in 1.11.0: `quote()`
| throws a `TypeError` when a string after a `{ comment }` token
| contains a line terminator.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102422
    https://www.cve.org/CVERecord?id=CVE-2026-102422
[1] 
https://github.com/ljharb/shell-quote/security/advisories/GHSA-pqg4-j6r4-53mv
[2] 
https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: node-shell-quote
Source-Version: 1.12.0-1
Done: Xavier Guimard <[email protected]>

We believe that the bug you reported is fixed in the latest version of
node-shell-quote, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-shell-quote package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 03 Oct 2026 07:36:07 +0200
Source: node-shell-quote
Architecture: source
Version: 1.12.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1149713
Changes:
 node-shell-quote (1.12.0-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1149713, CVE-2026-102422)
Checksums-Sha1: 
 92fb73ae6b036f5dcc308a51769596064d16e333 2097 node-shell-quote_1.12.0-1.dsc
 768c44f13ddab55a2967cb739556e2fc68563c38 32936 
node-shell-quote_1.12.0.orig.tar.gz
 542c15e673272646fb82bb03ad1bf0f26ac7bfec 3152 
node-shell-quote_1.12.0-1.debian.tar.xz
Checksums-Sha256: 
 2f5d78e08835ee541bb9d80d53967d32f8e59e6e0e5e9370d3734d8c70af1f6b 2097 
node-shell-quote_1.12.0-1.dsc
 615d46e99b0ea9d6ba73ecc19b6920962100f8053b06ec892b9623e19cbe451f 32936 
node-shell-quote_1.12.0.orig.tar.gz
 542e393fdd051601df04d9a0c2ccf89cb2176d388ffbc05dd87118b7693c5569 3152 
node-shell-quote_1.12.0-1.debian.tar.xz
Files: 
 a81954f3f2e301b555b01e287e189930 2097 javascript optional 
node-shell-quote_1.12.0-1.dsc
 31c5a09b3aeb0df8a6b8782ae4e9050b 32936 javascript optional 
node-shell-quote_1.12.0.orig.tar.gz
 69cebb818dc5c5ec1bbe586d0e44184e 3152 javascript optional 
node-shell-quote_1.12.0-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAlH0ACgkQ9tdMp8mZ
7um0QBAAgQVyXosHnSgLCYimKr/WSuyhGLv1lEZMHebcAcPZrZQrefEVu3os7v1Q
Oo4skziREgQI9TAQlDQ7aYzhzpjVAmPF/kAETYaDNvl0drXoKzqfcvuXOgtP9ock
0hCfGRWIEVyzVtNVtj1O1GgXq3xup4263idy/HZHHNnrZ7BfBYPtdUNXWoY/N2ky
DPVhmlWLCEU2A9Utmitmpi4N8zYc7GOa3gCG8aiCc2Vv22q8RVQEZPP2HCxWSha4
oJ73s4XMuqssxV1un91P5mpp7Ctd1DBV9kTTe+4ePixGqq9PURJtrOjhVIZOPPeI
U2Duv6wU6M1zeafjT671RWqzvcSMU9/GQPcd2rFrhwEP7k4Gf6oeSKbyeV3BdHQ/
pkXi9Y/YUqQmP4kJk58OBGvmyVoyCha3aT+NRvXzCB/rtnBHqf0c7TZ1KQJAqupf
MTqUK8v3V4eFh9d1GhacDBGU+IHaB/7xr4PfSRCTKOb6G+2xaUXLHQPS9JK3DFgS
VgWwz4QUK1u9fRkjkZiq35IXs/xlZVNdAT8ZrurHabG+S5xv8eBcZ7w3SxeCkexG
AxDWos9stNJiZ4RqvkG6OM78XJh8mqWzU5y0xIOUe/QUmujmrn77gZIJ5jJpkorM
gX9c3gWDZyUN/h0Y8TMbLdcUA4XTGJ2faQC7xEp+bej3t/2M7OQ=
=6q1L
-----END PGP SIGNATURE-----

Attachment: pgpDJWffFbZBj.pgp
Description: PGP signature


--- End Message ---
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to