{"id":"GHSA-g4rg-993r-mgx7","summary":"Improper Neutralization of Special Elements used in a Command in Shell-quote","details":"The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with `exec()`, an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is `[A-z]` instead of the correct `[A-Za-z]`. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.","aliases":["CVE-2021-42740"],"modified":"2026-07-17T21:16:58.689931512Z","published":"2022-05-24T19:18:27Z","database_specific":{"nvd_published_at":"2021-10-21T15:15:00Z","cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-06-21T20:08:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42740"},{"type":"WEB","url":"https://github.com/ljharb/shell-quote/commit/5799416ed454aa4ec9afafc895b4e31760ea1abe"},{"type":"PACKAGE","url":"https://github.com/ljharb/shell-quote"},{"type":"WEB","url":"https://github.com/ljharb/shell-quote/blob/master/CHANGELOG.md#173"},{"type":"WEB","url":"https://www.npmjs.com/package/shell-quote"}],"affected":[{"package":{"name":"shell-quote","ecosystem":"npm","purl":"pkg:npm/shell-quote"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.6.3"},{"fixed":"1.7.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.7.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g4rg-993r-mgx7/GHSA-g4rg-993r-mgx7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}