Description
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0328 | The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection. |
Github GHSA |
GHSA-qg8p-v9q4-gh34 | Potential Command Injection in shell-quote |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T03:18:50.154Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10541
No data.
Status : Modified
Published: 2018-05-31T20:29:01.503
Modified: 2024-11-21T02:44:13.863
Link: CVE-2016-10541
OpenCVE Enrichment
No data.
EUVD
Github GHSA