CVE-2026-9277Patch

MEDIUMCVSS 9.2 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 8d ago at 2 mentions (2026-05-23); latest day: 1
  • 11 total mentions across 9 days

Deep dive

Activity timeline11 mentions / 9d
01122Mentions · 2026-05-23: 2Mentions · 2026-05-28: 1Mentions · 2026-06-09: 2Mentions · 2026-06-11: 1Mentions · 2026-07-26: 1Mentions · 2026-08-15: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-10-02: 1Active Exploitation · 2026-06-11: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-28: 1Technical Details · 2026-06-09: 2Technical Details · 2026-07-26: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 105-2305-2806-0906-1107-2608-1508-2708-2810-02
Signal classification4 categories
Patch
660.0%
General
220.0%
Disclosure
110.0%
Active Exploitation
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-232
Disclosure1General1
2026-05-281
Patch1
2026-06-092
General1Patch1
2026-06-111
Active Exploitation1
2026-07-261
Patch1
2026-08-151
Patch1
2026-08-271
Patch1
2026-08-281
Patch1
Full discourse11 posts
  • kokumօtօ@__kokumoto
    Patch

    【即死系】npmパッケージshell-quoteに重大(Critical)なコマンドインジェクションの脆弱性。CVE-2026-9277はquote()において改行(\n)が認識されないもの。POSIXシェルでは改行はコマンド分割子として扱われるので終わり。バージョン1.1.0から1.8.3が脆弱。修正あり。 https://securityonline.info/shell-quote-command-injection-cve-2026-9277/

    Post summary

    CVE-2026-9277 is a critical command‑injection vulnerability in npm package shell‑quote (v1.1.0‑1.8.3). A patch has been released; there is no evidence of active exploitation or a publicly available PoC.

    030841.1K
    7.6K followersView on X
  • Repojournal@repojournal
    Patch

    React Native patched a critical shell-quote RCE (CVE-2026-9277). The fix upgrades shell-quote to 1.8.4 in #57663. If you bundle RN tooling, check your lockfile. Android builds now send a default User-Agent that includes the app name and version (#58147). Expect analytics and middleware to see slightly different traffic. roundLayoutResultsToPixelGrid now skips non-owned subtrees (#58144). A layout perf fix hiding in plain sight. Maestro Cloud screenshot flows skip device-specific runs (#58166). Less flaky CI, fewer red herrings. build-types support 'react-native/react-private-interface' (#58075). Cleaner interop for private API shims. Jest quietly migrates CoverageReporter tests off mock-fs. Test hygiene, but the direction is right. The shell-quote fix is the one to pull first. #javascript https://repojournal.com/showcase/meta/2026-08-28/react-native-patches-critical-shell-quote-rce

    Post summary

    React Native has patched the critical shell‑quote RCE (CVE‑2026‑9277) by upgrading to version 1.8.4; users should update their lockfiles—no PoC or active exploitation is reported.

    0304179
    422 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-9277: shell-quote before 1.8.4 command injection in quote() https://www.openwall.com/lists/oss-security/2026/05/23/2 /(.)/g in JavaScript does not match line terminators, so a newline can pass through unescaped. In POSIX shells, a literal newline is a command separator.

    Post summary

    The post announces CVE-2026-9277, detailing a command injection flaw in shell-quote v1.8.4 and a JavaScript regex quirk that enables newline-based bypass. No PoC, exploit tool, active exploitation, or patch information is provided.

    00071960
    4.7K followersView on X
  • Repojournal@repojournal
    Patch

    React Native's dev-time attack surface just got smaller. The CLI dependency shell-quote was bumped to 1.8.4, closing CVE-2026-9277, a command injection flaw. If you run RN's tooling on untrusted input, this one matters; update your lockfile. Meta also gutted two device-specific screenshot flows in RNTester, skipping them in Maestro Cloud (#58166). The CI runner for RNTester is now wired in (#58151), so the skip is part of a wider test-strategy shift. Jest's coverage reporter test migrated off mock-fs (#16401). It's a cleanup, but it de-risks a test path that depended on a virtual filesystem. The props-to-interface conversion continues. More types now back React's private interface (#58075), part of a slow, deliberate type cleanup. Nothing flashy, but the diff churn is steady. RN's tooling now has one less known hole. The screenshot flows being skipped suggest Maestro Cloud's own device matrix is handling coverage. Jest's mock-fs exit is the quiet housekeeping that keeps the test suite honest. Dependency bumps for CVEs are unglamorous. This one is the rare day where the fix beats the feature. #javascript https://repojournal.com/showcase/meta/2026-08-27/react-native-kills-two-feature-flags-as-jest-scrubs-a-supply-chain-advisory

    Post summary

    The post announces that React Native fixed CVE‑2026‑9277 by upgrading the shell‑quote dependency to 1.8.4 and recommends updating lockfiles; other changes are minor cleanup.

    0304073
    422 followersView on X
  • Repojournal@repojournal
    Patch

    shell-quote critical RCE vulnerability (CVE-2026-9277) patched in claude-code-action; bump to 1.8.4 shipped immediately. AWS plugin delisted from official registry. No detail on why, but the move was clean. PR review context now includes diff hunks, so Claude sees the actual changed lines when commenting on reviews. Matters more than it sounds. Image attachment downloads now bounded. Fetch depth logic tightened to avoid unnecessary deep clones on already-shallow checkouts. Spot plugins updated across the board: Pinecone, SonarQube, Spanner, and Carta suite all got bumps. Routine maintenance, but the cadence is steady. #AI https://repojournal.com/showcase/anthropics/2026-08-15/shell-quote-critical-vulnerability-patched-aws-plugin-delisted-pr-review

    Post summary

    The report announces that CVE-2026-9277, a shell-quote critical RCE, has been patched in claude-code-action with an immediate release; no exploitation or PoC information is provided.

    03040126
    427 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    🚨 A vulnerabilidade CVE-2026-9277 no shell-quote permitia injeção de comandos através de quebras de linha. Saiba mais -> https://tinyurl.com/y67n6kcj #Ubuntu https://t.co/tTLAc43bOy

    Post summary

    The post announces CVE-2026-9277 as a command injection flaw in shell-quote that exploits line‑breaks, providing a link for further details.

    1002063
    1.5K followersView on X
  • LinuxSecurity@lnxsec

    A dependency can be present everywhere and exploitable almost nowhere — or present once in exactly the wrong execution path. CVE-2026-9277 in shell-quote is a good example of why package inventory alone does not answer the operational question. The vulnerable path involves attacker-influenced object tokens reaching quote(), followed by the resulting string being handed to a POSIX shell. That distinction matters when triaging a large Node.js estate. Finding shell-quote <=1.8.3 is the beginning of the investigation, not the end. The more important question is where application data crosses into shell execution and under which Unix identity, container, runner, or service account that command executes. **In practical terms, it is a good time to:** - identify shell-quote versions in package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, and yarn.lock files - trace callers of quote() and parse() to determine whether object tokens can originate from external or transformed input - search Node.js code for child_process.exec(), execSync(), and shell: true near affected data flows - record the Unix user, capabilities, mounted secrets, and writable paths available to each reachable execution context - distinguish merely installed vulnerable packages from reachable vulnerable code in remediation tracking A vulnerability scanner can tell you where a package exists. How consistently can your team tell where its dangerous behavior is actually reachable? #LinuxSecurity #VulnerabilityManagement #DevSecOps #OpenSource #SecurityOperations https://linuxsecurity.com/news/security-vulnerabilities/shell-quote-command-injection-linux-commands

    0000081
    4.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    #CVE-2026-9277 (CVSS 8.1 HIGH): shell-quote library vulnerable to command injection via unvalidated object tokens. Line terminators in .op field bypass escaping, enabling arbitrary command execution. Patch immediately. #Vulnerability #PatchNow https://t.co/HDixfDZboM

    Post summary

    The tweet highlights CVE-2026-9277 as a high‑severity command injection flaw in the shell-quote library and urges users to apply a patch immediately.

    0000044
    96 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting shell-quote (CVE-2026-9277) https://vuldb.com/vuln/365199/cti

    Post summary

    The brief statement indicates that malicious actors have increased activity targeting the shell-quote vulnerability CVE-2026-9277, suggesting ongoing exploitation in the wild.

    0000065
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - shell-quote Command Injection Vulnerability (CVE-2026-9277) The shell-quote npm package contains a critical command injection vulnerability where the quote() function fails to escape line terminators (\n, \r) within object-token inputs. Successful exploitation could allow an attacker to bypass shell boundaries and execute arbitrary system commands with the privileges of the underlying Node.js process. 👉Affected: shell-quote >= 1.1.0, <= 1.8.3 | Fix: Upgrade to 1.8.4

    Post summary

    CVE-2026-9277 exposes a critical command injection flaw in shell-quote that could let attackers execute arbitrary system commands; users are urged to upgrade to version 1.8.4 to remediate.

    0000089
    207 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-9277 CVE-2026-9277 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9277

    Post summary

    The post merely lists the CVE identifier twice and links to a vulnerability details page, without providing concrete information about exploitation or mitigation.

    0000085
    4.0K followersView on X

Explore more