CVE-2026-102422: shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
### Impact `quote()` emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator in that later string ends the comment, and the rest of the string is parsed as shell input: ```js quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#']); // echo ok #x 'a // id;#' ``` Passed to `sh`, `bash`, `dash`, `ksh`, or `zsh`, this runs `id`. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Exploitation requires an attacker-controlled string containing a line terminator that follows a `{ comment }` token in the same `quote()` call. ### Patches Fixed in v1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator (`\n`, `\r`, U+2028, or U+2029). ### Workarounds Drop every token after a `{ comment }` token before calling `quote()`, or reject line terminators in untrusted strings. Separately, do not append other shell text after `quote()` output that contains a comment, since the comment swallows it.
Recommended action
Recommended action
Upgrade affected packages to a patched version: shell-quote 1.11.0.
Technical details
- Vendor
- Not specified
- Product
- shell-quote
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source