← Blog · · df00tech

shell-quote `quote()` Command Injection Bypass Resurfaces Fixed CVE-2026-9277 (CVE-2026-102422)

breaking ghsa npm CVE-2026-102422

What Happened

According to a GitHub Security Advisory (GHSA-pqg4-j6r4-53mv), the npm package shell-quote has a command injection vulnerability in its quote() function, tracked as CVE-2026-102422 (CVSS 8.1). A proof-of-concept is publicly available.

The advisory explains that quote() renders a { comment } token as # followed by the comment text, which comments out the rest of the shell line — including the opening quote of any string token that comes after it. If a later string token contains a line terminator (\n, \r, U+2028, or U+2029), that terminator ends the shell comment early, and the remainder of the string is parsed as live shell input. The advisory's example shows a token sequence producing output that, when passed to sh, bash, dash, ksh, or zsh, executes an injected id command.

Per the advisory, this is effectively a bypass of the fix for an earlier flaw, CVE-2026-9277, which rejected line terminators inside the comment token's own text but not inside tokens appearing after it. The advisory also notes that parse() emits comment tokens for a bare # mid-word (e.g., in a URL fragment), so code that combines parse() output with another untrusted string via quote() is also affected.

Why It Matters

shell-quote is a widely used npm dependency for safely constructing shell command strings. Any application that calls quote() with attacker-influenced input — directly as a { comment }-adjacent token, or indirectly by chaining parse() output with untrusted strings — and then executes the result via a shell, is exposed to arbitrary command execution. The exploitation precondition per the advisory is narrow but realistic: an attacker-controlled string containing a line terminator that follows a { comment } token within the same quote() call.

What Defenders Should Do Now

  • Inventory direct and transitive dependencies on shell-quote and confirm the installed version; the advisory states this is fixed in v1.11.0, where quote() throws a TypeError if a string after a { comment } token contains a line terminator.
  • Until patched, apply the advisory's workarounds: strip any tokens following a { comment } token before calling quote(), and reject line terminators in untrusted strings passed into it.
  • Review code paths that chain parse() output with additional untrusted strings before re-quoting, and avoid appending further shell text after quote() output that contains a comment.
  • At a detection level, consider hunting for anomalous child-process spawns from Node.js applications (e.g., sh -c/bash -c invocations) where command-line arguments contain embedded newlines or unexpected trailing shell metacharacters, as a general signal for this class of quoting-bypass injection.

Developing Intel

This is a same-day advisory and details may evolve as the ecosystem responds. For the authoritative technical write-up, patch version, and PoC, see the original GitHub Security Advisory: GHSA-pqg4-j6r4-53mv.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.