High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-13311
CVE-2026-13311
Description
shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required; plain space-separated words suffice) can block the single-threaded Node.js event loop for an extended period with a small input, resulting in a denial of service. There is no code execution or data disclosure; impact is to availability only. Fixed in 1.8.5.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shell-quotenpm | < 1.9.0 | 1.9.0 |
Affected products
13- cpe:2.3:a:shell-quote_project:shell-quote:*:*:*:*:*:node.js:*:*Range: <1.9.0
- Range: <1.8.5
- Range: <1.8.5
- osv-coords10 versionspkg:apk/chainguard/arangodb-3.12pkg:apk/chainguard/code-serverpkg:apk/chainguard/gemini-clipkg:apk/chainguard/gitlab-rails-ce-19.1pkg:apk/chainguard/gitlab-rails-ce-fips-18.1pkg:apk/wolfi/code-serverpkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/heroic-games-launcher&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-pytest-html&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-pytest-html&distro=openSUSE%20Tumbleweed
< 3.12.9.4-r13+ 9 more
- (no CPE)range: < 3.12.9.4-r13
- (no CPE)range: < 4.130.0-r3
- (no CPE)range: < 0.49.0-r7
- (no CPE)range: < 19.1.3-r4
- (no CPE)range: < 18.1.6-r68
- (no CPE)range: < 4.130.0-r3
- (no CPE)range: < 17+673.b97ba64d6-160000.12.1
- (no CPE)range: < 2.22.0-3.1
- (no CPE)range: < 4.1.1-bp160.3.1
- (no CPE)range: < 4.2.0-3.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-395f-4hp3-45gvghsaADVISORY
- github.com/ljharb/shell-quote/security/advisories/GHSA-395f-4hp3-45gvnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-13311ghsaADVISORY
- github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ecghsaWEB
- github.com/ljharb/shell-quote/releases/tag/v1.9.0ghsaWEB
- www.npmjs.com/package/shell-quotenvdProductWEB
News mentions
0No linked articles in our index yet.