CVE-2016-10541 is a critical code injection vulnerability affecting versions 1.6.0 and earlier of the npm module "shell-quote," as well as applications that rely on it. The flaw stems from the module's inability to properly escape the ">" and "<" shell redirection operators. With a CVSS score of 9.8 (Critical), this vulnerability allows unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, requiring no user interaction. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness despite no active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:shell-quote_project:shell-quote:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.