Shell-Quote
Shell-Quote Project · 3 CVEs
CVE-2026-13311
HIGH
shell-quote parse() is quadratic in token count, enabling denial of service
Jun 25, 2026
CVE-2021-42740
CRITICAL
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metac…
Oct 21, 2021
CVE-2016-10541
CRITICAL
nodejs-shell-quote: Command Injection via bash escape characters
May 31, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-13311 | shell-quote parse() is quadratic in token count, enabling denial of service | HIGH | 0.60% | Jun 25, 2026 |
| CVE-2021-42740 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to su… | CRITICAL | 4.22% | Oct 21, 2021 |
| CVE-2016-10541 | nodejs-shell-quote: Command Injection via bash escape characters | CRITICAL | 2.25% | May 31, 2018 |
Showing 1 to 3 of 3 CVEs