CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102422

HIGHCVSS 8.1NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102422 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102422

HIGHCVSS 8.1NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]