https://seclists.org/oss-sec/2026/q2/674: CVE-2026-9277: shell-quote befo1.8.4 command injection in quote()
Published May 23, 2026
·Updated
Affected Software
1 affected component
npm/shell-quote<=1.8.3
Frequently Asked Questions
1
What is the severity of CVE-2026-9277?
CVE-2026-9277 has a CVSS v3.1 score of 8.1, indicating a high severity vulnerability.
2
How do I fix CVE-2026-9277?
To fix CVE-2026-9277, upgrade to shell-quote version 1.8.4 or later.
3
What types of applications are affected by CVE-2026-9277?
Applications that use shell-quote versions prior to 1.8.4 and pass attacker-influenced .op values to the quote() function are affected.
4
What is the impact of CVE-2026-9277?
The impact of CVE-2026-9277 is the potential for command injection through a POSIX shell, allowing attackers to execute arbitrary commands.
5
When was CVE-2026-9277 published?
CVE-2026-9277 was published on May 23, 2026.