Disclosure summary
### Impact `quote()` emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator in that later string ends the comment, and the rest of the string is parsed as shell input: ```js quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#']); // echo ok #x 'a // id;#' ``` Passed to `sh`, `bash`, `dash`, `ksh`, or `zsh`, this runs `id`. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Exploitation requires an attacker-controlled string containing a line terminator that follows a `{ comment }` token in the same `quote()` call. ### Patches Fixed in v1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator (`\n`, `\r`, U+2028, or U+2029). ### Workarounds Drop every token after a `{ comment }` token before calling `quote
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-pqg4-j6r4-53mv
Open original source · Updated Oct 06, 2026
shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
Source severity: CRITICAL / 9.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | shell-quote | >= 1.8.4, < 1.11.0 | 1.11.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-06T09:40:36-04:00
MODIFIED 2026-10-06T09:40:37-04:00
INGESTED 2026-10-06T11:45:43-04:00