Back

CRITICAL

shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

Published May 22, 2026

Description

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.

Affected products

Remediation

No remediation recorded yet.

References (43)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner harborist
Published May 22, 2026
Updated Sep 14, 2026
Reserved May 22, 2026

CISA Vulnrichment

Updated May 22, 2026

NVD

Status Deferred
Modified Sep 14, 2026

Red Hat

Severity Important
Public date May 22, 2026
Bugzilla 2480741

ENISA EUVD

Assigner harborist
Published May 22, 2026
Updated Sep 14, 2026