Skip to main content

Vendor/product archive

shell-quote_project / shell-quote CVEs

Beta · best-effort

3 CVEs tagged to shell-quote_project / shell-quote2 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-13311

Published Jun 25, 2026

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-42740

Published Oct 21, 2021

The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10541

Published May 31, 2018

The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vuln…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1