CVE-2026-9277
Vulnerability Summary
Timeline
Description
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.
CVSS Metrics
- v4.0•CRITICAL•Score: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- v4.0•CRITICAL•Score: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.85%• Percentile: 57%
Techniques & Countermeasures
- CWE-77•Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
- CWE-78•Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Affected Systems
- chainguard•arangodb-3.11
< 3.11.14.4-r9
- chainguard•arangodb-3.12
< 3.12.9.4-r2
- chainguard•argo-workflows-ui-3.6
< 3.6.19-r7
- chainguard•code-server
< 4.123.0-r2
- chainguard•gemini-cli
< 0.49.0-r4
- chainguard•gitlab-rails-ce-18.1
< 18.1.6-r20
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
< 18.11.6-r8
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
< 19.0.4-r4
- chainguard•gitlab-rails-ce-19.1
< 19.1.2-r4
- chainguard•gitlab-rails-ce-fips-18.1
< 18.1.6-r68
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
< 18.11.7-r2
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
< 19.0.4-r4
- chainguard•gitlab-rails-ce-fips-19.1
< 19.1.2-r5
- chainguard•langfuse-2-worker
< 2.95.12-r28
- chainguard•py3.10-captum
< 0.9.0-r1
- chainguard•py3.11-captum
< 0.9.0-r1
- chainguard•py3.12-captum
< 0.9.0-r1
- chainguard•py3.13-captum
< 0.9.0-r1
- chainguard•tileserver-gl
< 5.6.0-r5
- chainguard•tileserver-gl-fips
< 5.6.0-r4
- wolfi•code-server
< 4.123.0-r2
- wolfi•tileserver-gl
< 5.6.0-r5
- debian•node-shell-quote
< 1.7.4+~1.7.1-1+deb12u1 | < 1.7.4+~1.7.1-1+deb13u1 | < 1.8.4+~1.7.5-1
- Npm•shell-quote
≥ 1.1.0, < 1.8.4
References (43)
- https://github.com/ljharb/shell-quote/security/advisories/GHSA-w7jw-789q-3m8p
- https://github.com/ljharb/shell-quote/commit/1518179
- https://github.com/ljharb/shell-quote
- https://www.npmjs.com/package/shell-quote
- http://www.openwall.com/lists/oss-security/2026/05/23/2
- https://nvd.nist.gov/vuln/detail/CVE-2026-9277
- https://access.redhat.com/security/cve/CVE-2026-9277
- https://bugzilla.redhat.com/show_bug.cgi?id=2480741
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9277.json
- https://access.redhat.com/errata/RHSA-2026:28010
- https://access.redhat.com/errata/RHSA-2026:26234
- https://access.redhat.com/errata/RHSA-2026:29197
- https://access.redhat.com/errata/RHSA-2026:26072
- https://access.redhat.com/errata/RHSA-2026:26080
- https://access.redhat.com/errata/RHSA-2026:26077
- https://access.redhat.com/errata/RHSA-2026:26079
- https://access.redhat.com/errata/RHSA-2026:26090
- https://access.redhat.com/errata/RHSA-2026:30076
- https://access.redhat.com/errata/RHSA-2026:28571
- https://access.redhat.com/errata/RHSA-2026:26225
- https://access.redhat.com/errata/RHSA-2026:34342
- https://access.redhat.com/errata/RHSA-2026:33574
- https://access.redhat.com/errata/RHSA-2026:34791
- https://access.redhat.com/errata/RHSA-2026:29834
- https://access.redhat.com/errata/RHSA-2026:29795
- https://access.redhat.com/errata/RHSA-2026:33683
- https://access.redhat.com/errata/RHSA-2026:36754
- https://access.redhat.com/errata/RHSA-2026:41066
- https://access.redhat.com/errata/RHSA-2026:41928
- https://access.redhat.com/errata/RHSA-2026:42796
- https://access.redhat.com/errata/RHSA-2026:50850
- https://access.redhat.com/errata/RHSA-2026:48699
- https://access.redhat.com/errata/RHSA-2026:40765
- https://access.redhat.com/errata/RHSA-2026:44263
- https://access.redhat.com/errata/RHSA-2026:44267
- https://access.redhat.com/errata/RHSA-2026:44237
- https://security-tracker.debian.org/tracker/CVE-2026-9277
- https://access.redhat.com/errata/RHSA-2026:56912
- https://access.redhat.com/errata/RHSA-2026:56854
- https://access.redhat.com/errata/RHSA-2026:62260
- https://access.redhat.com/errata/RHSA-2026:60023
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9277.json
- https://access.redhat.com/errata/RHSA-2026:62410