The Shell Quote Project maintains a narrowly scoped utility library focused on shell-quoting and escaping functionality, a niche component that sees adoption in scripting and command-execution contexts across multiple programming ecosystems. While the product footprint is small, its embedded role in downstream tooling means disclosed vulnerabilities warrant attention from maintainers of dependent projects; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shell Quote Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13311HIGH shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every i | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2016-10541CRITICAL The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulne | May 31, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-42740CRITICAL The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive l | Oct 21, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shell Quote Project.
Media articles that mention a CVE ID that affects a product developed by Shell Quote Project — matched by CVE ID, not by vendor name.