External risk intelligence

Shell-Quote Quote Function Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-102422

This vulnerability is in a code library (shell-quote) used by developers to programmatically quote shell arguments. It is not an internet-facing service, application, or appliance. Exposure depends entirely on whether a developer incorporates the library into an application that processes untrusted input in a specific, vulnerable way, which is a build-time and architectural implementation detail.

OS Command Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a code library used for securely handling command-line arguments. If applications improperly use this library to process untrusted input, an attacker could potentially execute arbitrary commands on affected systems by crafting specific input that bypasses security controls. The main concern is confirming whether this library is used and if it's implemented in a way that exposes this weakness.

  • Input processing can be maliciously manipulated.
  • Leadership should remember to verify library usage.
  • Confirm relevance and exposure of this library.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by providing specially crafted input to an application that uses the `shell-quote` library. If the application combines the output of parsing untrusted input with another untrusted string using the `quote()` function, the attacker can inject shell commands. This occurs because a comment token can be terminated by a newline character within a subsequent string, allowing the injected text to be executed as shell commands.

  • Requires application using the library to process untrusted input.
  • Triggered by crafted input to the `quote()` function.
  • Allows arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to inject and execute arbitrary shell commands when a vulnerable application processes specially crafted input. This occurs when the `quote()` function in the `shell-quote` library mishandles comment tokens containing line terminators, allowing subsequent parts of the input to be interpreted as commands.

  • Arbitrary shell commands may be executed.
  • User input could be processed in unexpected ways.
  • Impact depends on application integration.

Operational Fix

Recommended remediation, mitigation, and detection steps

The `shell-quote` library's `quote()` function is susceptible to command injection if used with untrusted input containing line terminators. Technical leaders and security teams must first identify all applications utilizing this library, determine if they process external data that could trigger the vulnerability, and ascertain the business criticality of those applications. This information is essential for prioritizing and planning remediation efforts with the responsible development or platform teams, potentially involving vendor coordination if `shell-quote` is a third-party dependency.

  • Application development teams own the issue.
  • Verify vulnerable library usage in applications.
  • Plan remediation based on application risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the shell-quote library?

shell-quote is a software library designed for Node.js environments. Developers use it to safely format strings into shell arguments, ensuring that special characters are escaped correctly so they do not break command-line execution or introduce security flaws when processed by shell interpreters like bash or zsh.

How does CVE-2026-102422 cause a command injection vulnerability?

This flaw belongs to the OS Command Injection class (CWE-78). The library's quote() function incorrectly handles comment tokens. An attacker can craft input that embeds a comment followed by a line terminator, which forces the shell to ignore the intended quoting and instead execute subsequent text as a new, unauthorized command.

Does any input to the library trigger this vulnerability?

No. The vulnerability only triggers when an application uses the library to combine the output of parse() with other untrusted strings or specifically passes input containing both a comment structure and a line terminator. Simple, static command quoting without these specific complex, nested input conditions does not trigger the execution of arbitrary commands.

Is my system at risk if I run software using shell-quote?

Halo Surface Signal notes that this is a developer library, not an internet-facing appliance. Your risk depends entirely on whether your custom applications take untrusted user input and pass it through the vulnerable quote() function sequence. It is not an automatic 'on or off' exposure for your infrastructure.

How should I respond to this threat advisory?

Start by identifying which internal applications include shell-quote as a dependency. Once located, work with development teams to check if those applications pass untrusted, external data into the quote() function. If they do, plan to update the library to version 1.11.0 or higher, which includes the fix to prevent line terminators after comment tokens.

References