Impact
The shell-quote library’s quote() function generates a comment token (#) that comments out the remainder of the shell line. If a line terminator (\n, \r, U+2028, U+2029) appears in a subsequent string token, the comment ends at that point, causing the remainder of the string to be parsed as active shell input. Malicious callers that supply untrusted data to quote() or combine parse() output with untrusted arguments can therefore inject arbitrary shell commands such as id, resulting in full command execution in the context of the running process. This vulnerability is a classic command injection flaw, represented by CWE‑78.
Affected Systems
This issue affects the npm package shell-quote for all Node.js applications that use the quote() or parse() functions to construct shell commands. Versions prior to 1.11.0 are vulnerable; version 1.11.0 and later contain a guard that throws a TypeError when a string following a { comment } token contains a line terminator.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.2, indicating high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports yet. Nevertheless, the flaw is exploitable in any context where untrusted user input is passed to quote() or parse() and concatenated with other command components, without additional validation. Attackers could exploit this remotely if the application accepts user-controlled input that eventually flows to shell-quote; no privileged access is required beyond the execution context of the vulnerable process.
OpenCVE Enrichment