shell-quote `quote()` Command Injection Bypass Resurfaces Fixed CVE-2026-9277 (CVE-2026-102422)
What Happened
According to a GitHub Security Advisory (GHSA-pqg4-j6r4-53mv), the npm package shell-quote has a command injection vulnerability in its quote() function, tracked as CVE-2026-102422 (CVSS 8.1). A proof-of-concept is publicly available.
The advisory explains that quote() renders a { comment } token as # followed by the comment text, which comments out the rest of the shell line — including the opening quote of any string token that comes after it. If a later string token contains a line terminator (\n, \r, U+2028, or U+2029), that terminator ends the shell comment early, and the remainder of the string is parsed as live shell input. The advisory's example shows a token sequence producing output that, when passed to sh, bash, dash, ksh, or zsh, executes an injected id command.
Per the advisory, this is effectively a bypass of the fix for an earlier flaw, CVE-2026-9277, which rejected line terminators inside the comment token's own text but not inside tokens appearing after it. The advisory also notes that parse() emits comment tokens for a bare # mid-word (e.g., in a URL fragment), so code that combines parse() output with another untrusted string via quote() is also affected.
Why It Matters
shell-quote is a widely used npm dependency for safely constructing shell command strings. Any application that calls quote() with attacker-influenced input — directly as a { comment }-adjacent token, or indirectly by chaining parse() output with untrusted strings — and then executes the result via a shell, is exposed to arbitrary command execution. The exploitation precondition per the advisory is narrow but realistic: an attacker-controlled string containing a line terminator that follows a { comment } token within the same quote() call.
What Defenders Should Do Now
- Inventory direct and transitive dependencies on
shell-quoteand confirm the installed version; the advisory states this is fixed in v1.11.0, wherequote()throws aTypeErrorif a string after a{ comment }token contains a line terminator. - Until patched, apply the advisory's workarounds: strip any tokens following a
{ comment }token before callingquote(), and reject line terminators in untrusted strings passed into it. - Review code paths that chain
parse()output with additional untrusted strings before re-quoting, and avoid appending further shell text afterquote()output that contains a comment. - At a detection level, consider hunting for anomalous child-process spawns from Node.js applications (e.g.,
sh -c/bash -cinvocations) where command-line arguments contain embedded newlines or unexpected trailing shell metacharacters, as a general signal for this class of quoting-bypass injection.
Developing Intel
This is a same-day advisory and details may evolve as the ecosystem responds. For the authoritative technical write-up, patch version, and PoC, see the original GitHub Security Advisory: GHSA-pqg4-j6r4-53mv.