AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102422.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

### Impact `quote()` emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator in that later string ends the comment, and the rest of the string is parsed as shell input: ```js quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#']); // echo ok #x 'a // id;#' ``` Passed to `sh`, `bash`, `dash`, `ksh`, or `zsh`, this runs `id`. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Exploitation requires an attacker-controlled string containing a line terminator that follows a `{ comment }` token in the same `quote()` call. ### Patches Fixed in v1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator (`\n`, `\r`, U+2028, or U+2029). ### Workarounds Drop every token after a `{ comment }` token before calling `quote

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-pqg4-j6r4-53mv

Open original source · Updated Oct 06, 2026

shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token

Source severity: CRITICAL / 9.2

EcosystemPackageAffected rangeFirst patched
npmshell-quote>= 1.8.4, < 1.11.01.11.0

Original records & references

PUBLISHED 2026-10-06T09:40:36-04:00
MODIFIED 2026-10-06T09:40:37-04:00
INGESTED 2026-10-06T11:45:43-04:00