Skip to content
Noroxi

shell-quote project records

3 published records for vendor shell-quote project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

3 records
  • The shell-quote package before 1.7.3 for Node.js allows command injection.

    CriticalCVSS 9.8No exploitEPSS 4%

    shell-quote project · shell-quoteOct 21, 2021

  • The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell.

    CriticalCVSS 9.8No exploitEPSS 2%

    shell-quote project · shell-quoteMay 31, 2018

  • shell-quote parse() is quadratic in token count, enabling denial of service

    HighCVSS 8.7No exploitEPSS 0%

    shell-quote project · shell-quoteJun 25, 2026