Critical severity9.8NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10541
CVE-2016-10541
Description
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shell-quotenpm | < 1.6.1 | 1.6.1 |
Affected products
9- cpe:2.3:a:shell-quote_project:shell-quote:*:*:*:*:*:node.js:*:*Range: <1.6.1
- osv-coords7 versionspkg:apk/chainguard/jitsucom-jitsupkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/jitsucom-jitsu-rotorpkg:apk/wolfi/jitsucom-jitsupkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/wolfi/jitsucom-jitsu-rotorpkg:npm/shell-quote
< 0+ 6 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.6.1
- HackerOne/shell-quote node modulev5Range: <=1.6.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-qg8p-v9q4-gh34nvdExploitThird Party AdvisoryADVISORY
- nodesecurity.io/advisories/117nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2016-10541ghsaADVISORY
- www.npmjs.com/advisories/117ghsaWEB
News mentions
0No linked articles in our index yet.