Back

CRITICAL

shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token

Published Sep 29, 2026

Description

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is parsed as shell input: `quote(['echo', 'ok', { comment: 'x' }, 'a\nid;#'])` runs `id` in sh, bash, dash, ksh and zsh. `parse()` emits a comment token for a `#` in the middle of a word (for example `http://example.com/#frag`), so callers that combine `parse()` output with another untrusted string, such as `quote(parse(untrustedCommand).concat(untrustedArg))`, are affected. The fix for CVE-2026-9277 rejected line terminators in the comment's own text, but not in the tokens after it. Fixed in 1.11.0: `quote()` throws a `TypeError` when a string after a `{ comment }` token contains a line terminator.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner harborist
Published Sep 29, 2026
Updated Sep 30, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 29, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner harborist
Published Oct 6, 2026
Updated Oct 6, 2026
Exploited since n/a
EUVD-2026-88629 GHSA-PQG4-J6R4-53MV