Executive brief
The shell-quote library, a popular tool for preparing commands to run in a system shell, contains a vulnerability that fails to properly clean certain inputs. An attacker can exploit this by injecting hidden commands using line breaks, which a system shell may then execute as separate, unauthorized instructions. This could lead to full system compromise or unauthorized data access depending on how the library is used in an application.
Technical details
A command injection vulnerability exists in shell-quote's `quote()` function due to improper neutralization of line terminators (\n, \r, U+2028, U+2029) within the `.op` field of object tokens. The function used a per-character backslash-escaping regex `/(.)/g` which, in JavaScript, does not match line terminators, allowing them to pass into the output unescaped. Because POSIX shells treat newlines as command separators, an attacker can inject arbitrary commands if the application passes attacker-influenced object tokens to `quote()`. This is reachable via direct construction of object tokens or through the `parse()` function's `envFn` callback. The issue is fixed in version 1.8.4 by implementing strict allowlist validation for the `.op` field and other object shapes.
Affected products
- ljharb shell-quote >= 1.1.0, <= 1.8.3
Timeline
- 2026-05-09: disclosed: Issue reported to maintainer
- 2026-05-22: patched: Version 1.8.4 released
- 2026-05-22: advisory: GitHub Security Advisory published
References
- https://www.npmjs.com/package/shell-quote
- https://github.com/ljharb/shell-quote
- https://github.com/ljharb/shell-quote/commit/1518179
- https://github.com/ljharb/shell-quote/security/advisories/GHSA-w7jw-789q-3m8p
- http://www.openwall.com/lists/oss-security/2026/05/23/2
- https://access.redhat.com/errata/RHSA-2026:26072
- https://access.redhat.com/errata/RHSA-2026:26077