Le 02/10/2026 à 16:51, Salvatore Bonaccorso a écrit :
Source: node-shell-quote
Version: 1.10.0-1
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for node-shell-quote.

CVE-2026-102422[0]:

Hi,

here is the debdiff. If you don't consider it as urgent, of course I can push it to release.debian.org.

Best regards,
Xavier
diff --git a/debian/changelog b/debian/changelog
index 77a8617..f537f1f 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,9 @@
+node-shell-quote (1.10.0-1+deb13u1) trixie-security; urgency=medium
+
+  * Reject line terminators in tokens after a comment (Closes: #1149713, 
CVE-2026-102422)
+
+ -- Xavier Guimard <[email protected]>  Sat, 03 Oct 2026 07:44:45 +0200
+
 node-shell-quote (1.10.0-1) unstable; urgency=medium
 
   * Team upload
diff --git a/debian/patches/CVE-2026-102422.patch 
b/debian/patches/CVE-2026-102422.patch
new file mode 100644
index 0000000..94fcd70
--- /dev/null
+++ b/debian/patches/CVE-2026-102422.patch
@@ -0,0 +1,83 @@
+Description: reject line terminators in tokens after a comment
+Author: Jordan Harband <[email protected]>
+Origin: upstream, https://github.com/ljharb/shell-quote/commit/6002b2ed
+Bug: https://www.cve.org/CVERecord?id=CVE-2026-102422
+Bug-Debian: https://bugs.debian.org/1149713
+Forwarded: not-needed
+Applied-Upstream: 1.12.0, commit:6002b2ed
+Reviewed-By: Xavier Guimard <[email protected]>
+
+--- a/README.md
++++ b/README.md
+@@ -125,8 +125,9 @@
+ `parse` emits: `{ op }` (where `op` is one of the control operators
+ `||`, `&&`, `;;`, `|&`, `<(`, `<<<`, `>>`, `>&`, `<&`, `&`, `;`, `(`,
+ `)`, `|`, `<`, `>`), `{ op: 'glob', pattern }`, or `{ comment }`. Any
+-other object shape, an unrecognized `op`, or a `pattern`/`comment`
+-containing line terminators throws a `TypeError`.
++other object shape, an unrecognized `op`, a `pattern`/`comment`
++containing line terminators, or a string containing line terminators
++anywhere after a `{ comment }` throws a `TypeError`.
+ 
+ The output is POSIX shell (`sh`/`bash`) quoting.
+ It is not valid for Windows `cmd.exe` or PowerShell,
+--- a/quote.js
++++ b/quote.js
+@@ -26,7 +26,11 @@
+ 
+ /** @type {typeof import('./quote')} */
+ module.exports = function quote(xs) {
++      var sawComment = false;
+       return xs.map(function (s) {
++              if (sawComment && typeof s === 'string' && 
LINE_TERMINATORS.test(s)) {
++                      throw new TypeError('a token after a `comment` must not 
contain line terminators');
++              }
+               if (s === '') {
+                       return /** @type {const} */ ('\'\'');
+               }
+@@ -50,6 +54,7 @@
+                               if (LINE_TERMINATORS.test(s.comment)) {
+                                       throw new TypeError('`comment` must not 
contain line terminators');
+                               }
++                              sawComment = true;
+                               return '#' + s.comment;
+                       }
+                       throw new TypeError('unrecognized object token shape');
+--- a/test/quote.js
++++ b/test/quote.js
+@@ -2,6 +2,7 @@
+ 
+ var test = require('tape');
+ var quote = require('../').quote;
++var parse = require('../').parse;
+ 
+ test('quote', function (t) {
+       t.equal(quote(['a', 'b', 'c d']), 'a b \'c d\'');
+@@ -137,6 +138,27 @@
+       t.end();
+ });
+ 
++test('quote comment: rejects line terminators in later tokens', function (t) {
++      t['throws'](function () { quote(['echo', { comment: 'x' }, 'a\nid;#']); 
}, TypeError, 'newline after a comment');
++      t['throws'](function () { quote(['echo', { comment: 'x' }, 'a\rb']); }, 
TypeError, 'CR after a comment');
++      t['throws'](function () { quote(['echo', { comment: 'x' }, 
'a\u2028b']); }, TypeError, 'U+2028 after a comment');
++      t['throws'](function () { quote(['echo', { comment: 'x' }, 
'a\u2029b']); }, TypeError, 'U+2029 after a comment');
++      t['throws'](
++              function () { quote(['echo', { comment: 'x' }, 'ok', 
'it\'s\nid;#']); },
++              TypeError,
++              'newline in any later token, not just the next one'
++      );
++      t['throws'](
++              function () { quote(parse('curl 
http://x/#frag').concat('a\nid;#')); },
++              TypeError,
++              'a mid-word `#` from parse, followed by an appended token'
++      );
++
++      t.equal(quote(['echo', 'a\nb', { comment: 'x' }]), 'echo \'a\nb\' #x', 
'a line terminator before a comment is fine');
++      t.equal(quote(['echo', { comment: 'x' }, 'y']), 'echo #x y', 'later 
tokens without line terminators are unchanged');
++      t.end();
++});
++
+ test('quote rejects unrecognized object shapes', function (t) {
+       t['throws'](function () { quote([{}]); }, TypeError, 'empty object');
+       t['throws'](function () { quote([{ foo: 'bar' }]); }, TypeError, 
'unknown key');
diff --git a/debian/patches/series b/debian/patches/series
new file mode 100644
index 0000000..a0af3ee
--- /dev/null
+++ b/debian/patches/series
@@ -0,0 +1 @@
+CVE-2026-102422.patch
-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to