Vulnerability record · CVE-2021-42740 · published 21 October 2021
CVE-2021-42740: Shell-quote project shell-quote command injection vulnerability
SShell Quote Project · Shell Quote
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.
Description
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command with exec(), an attacker can inject arbitrary commands. This is because the Windows drive letter regex character class is {A-z] instead of the correct {A-Za-z]. Several shell metacharacters exist in the space between capital letter Z and lower case letter a, such as the backtick character.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/substack/node-shell-quote/blob/master/CHANGELOG.md#173 | Third Party Advisory |
| https://github.com/substack/node-shell-quote/commit/5799416ed454aa4ec9afafc895b4e31760ea1abe | PatchThird Party Advisory |
| https://www.npmjs.com/package/shell-quote | Vendor Advisory |
| https://github.com/substack/node-shell-quote/blob/master/CHANGELOG.md#173 | Third Party Advisory |
| https://github.com/substack/node-shell-quote/commit/5799416ed454aa4ec9afafc895b4e31760ea1abe | PatchThird Party Advisory |
| https://www.npmjs.com/package/shell-quote | Vendor Advisory |
Track CVE-2021-42740 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42740), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.