OS Command Injection in shell-quote - CVE-2026-102422
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the quote() function when processing an attacker-controlled string containing a line terminator after a { comment } token. A remote attacker can supply a crafted token sequence to execute arbitrary commands.
Exploitation requires the line terminator to follow a { comment } token in the same quote() call.