Le 02/10/2026 à 16:51, Salvatore Bonaccorso a écrit :
Source: node-shell-quote
Version: 1.10.0-1
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security upstream
Hi,
The following vulnerability was published for node-shell-quote.
CVE-2026-102422[0]:
Hi,
here is the debdiff. If you don't consider it as urgent, of course I can
push it to release.debian.org.
Best regards,
Xavier
diff --git a/debian/changelog b/debian/changelog
index 77a8617..f537f1f 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,9 @@
+node-shell-quote (1.10.0-1+deb13u1) trixie-security; urgency=medium
+
+ * Reject line terminators in tokens after a comment (Closes: #1149713,
CVE-2026-102422)
+
+ -- Xavier Guimard <[email protected]> Sat, 03 Oct 2026 07:44:45 +0200
+
node-shell-quote (1.10.0-1) unstable; urgency=medium
* Team upload
diff --git a/debian/patches/CVE-2026-102422.patch
b/debian/patches/CVE-2026-102422.patch
new file mode 100644
index 0000000..94fcd70
--- /dev/null
+++ b/debian/patches/CVE-2026-102422.patch
@@ -0,0 +1,83 @@
+Description: reject line terminators in tokens after a comment
+Author: Jordan Harband <[email protected]>
+Origin: upstream, https://github.com/ljharb/shell-quote/commit/6002b2ed
+Bug: https://www.cve.org/CVERecord?id=CVE-2026-102422
+Bug-Debian: https://bugs.debian.org/1149713
+Forwarded: not-needed
+Applied-Upstream: 1.12.0, commit:6002b2ed
+Reviewed-By: Xavier Guimard <[email protected]>
+
+--- a/README.md
++++ b/README.md
+@@ -125,8 +125,9 @@
+ `parse` emits: `{ op }` (where `op` is one of the control operators
+ `||`, `&&`, `;;`, `|&`, `<(`, `<<<`, `>>`, `>&`, `<&`, `&`, `;`, `(`,
+ `)`, `|`, `<`, `>`), `{ op: 'glob', pattern }`, or `{ comment }`. Any
+-other object shape, an unrecognized `op`, or a `pattern`/`comment`
+-containing line terminators throws a `TypeError`.
++other object shape, an unrecognized `op`, a `pattern`/`comment`
++containing line terminators, or a string containing line terminators
++anywhere after a `{ comment }` throws a `TypeError`.
+
+ The output is POSIX shell (`sh`/`bash`) quoting.
+ It is not valid for Windows `cmd.exe` or PowerShell,
+--- a/quote.js
++++ b/quote.js
+@@ -26,7 +26,11 @@
+
+ /** @type {typeof import('./quote')} */
+ module.exports = function quote(xs) {
++ var sawComment = false;
+ return xs.map(function (s) {
++ if (sawComment && typeof s === 'string' &&
LINE_TERMINATORS.test(s)) {
++ throw new TypeError('a token after a `comment` must not
contain line terminators');
++ }
+ if (s === '') {
+ return /** @type {const} */ ('\'\'');
+ }
+@@ -50,6 +54,7 @@
+ if (LINE_TERMINATORS.test(s.comment)) {
+ throw new TypeError('`comment` must not
contain line terminators');
+ }
++ sawComment = true;
+ return '#' + s.comment;
+ }
+ throw new TypeError('unrecognized object token shape');
+--- a/test/quote.js
++++ b/test/quote.js
+@@ -2,6 +2,7 @@
+
+ var test = require('tape');
+ var quote = require('../').quote;
++var parse = require('../').parse;
+
+ test('quote', function (t) {
+ t.equal(quote(['a', 'b', 'c d']), 'a b \'c d\'');
+@@ -137,6 +138,27 @@
+ t.end();
+ });
+
++test('quote comment: rejects line terminators in later tokens', function (t) {
++ t['throws'](function () { quote(['echo', { comment: 'x' }, 'a\nid;#']);
}, TypeError, 'newline after a comment');
++ t['throws'](function () { quote(['echo', { comment: 'x' }, 'a\rb']); },
TypeError, 'CR after a comment');
++ t['throws'](function () { quote(['echo', { comment: 'x' },
'a\u2028b']); }, TypeError, 'U+2028 after a comment');
++ t['throws'](function () { quote(['echo', { comment: 'x' },
'a\u2029b']); }, TypeError, 'U+2029 after a comment');
++ t['throws'](
++ function () { quote(['echo', { comment: 'x' }, 'ok',
'it\'s\nid;#']); },
++ TypeError,
++ 'newline in any later token, not just the next one'
++ );
++ t['throws'](
++ function () { quote(parse('curl
http://x/#frag').concat('a\nid;#')); },
++ TypeError,
++ 'a mid-word `#` from parse, followed by an appended token'
++ );
++
++ t.equal(quote(['echo', 'a\nb', { comment: 'x' }]), 'echo \'a\nb\' #x',
'a line terminator before a comment is fine');
++ t.equal(quote(['echo', { comment: 'x' }, 'y']), 'echo #x y', 'later
tokens without line terminators are unchanged');
++ t.end();
++});
++
+ test('quote rejects unrecognized object shapes', function (t) {
+ t['throws'](function () { quote([{}]); }, TypeError, 'empty object');
+ t['throws'](function () { quote([{ foo: 'bar' }]); }, TypeError,
'unknown key');
diff --git a/debian/patches/series b/debian/patches/series
new file mode 100644
index 0000000..a0af3ee
--- /dev/null
+++ b/debian/patches/series
@@ -0,0 +1 @@
+CVE-2026-102422.patch
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel