Skip to content

fix(deps): bump shell-quote to 1.12.0 to address CVE-2026-102422 - #625

Closed
Mayvis wants to merge 2 commits into
open-cli-tools:mainfrom
Mayvis:fix/bump-shell-quote
Closed

Mayvis wants to merge 2 commits into
open-cli-tools:mainfrom
Mayvis:fix/bump-shell-quote

Conversation

@Mayvis

@Mayvis Mayvis commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Closes #626

Summary

Bumps shell-quote from 1.9.0 to 1.12.0 to address CVE-2026-102422 / GHSA-pqg4-j6r4-53mv (critical): quote() command injection via a line terminator in a token after a { comment } token.

  • Affected versions: >=1.8.4 <1.11.0
  • First patched version: 1.11.0

concurrently uses quote() from shell-quote in lib/command-parser/expand-arguments.ts.

Compatibility

concurrently only calls quote() in lib/command-parser/expand-arguments.ts, to escape passthrough arguments substituted into the {1}, {@} and {*} placeholders, and it always passes an array of strings.

Changes in quote.js between 1.9.0 and 1.12.0:

  • Object-token changes: the CVE fix (line-terminator check after { comment }), new operators and glob handling only apply to object tokens, so they never apply to concurrently.
  • String output: I compared outputs for common inputs (spaces, ", $, backticks, ~, backslashes, newlines, empty string, etc.) and they are identical.
  • The only difference: strings that contain both ' and !, e.g. it's great!:
Version quote() output Value seen by sh/bash
1.9.0 "it's great\!" it's great\! (stray backslash, wrong)
1.12.0 'it'"'"'s great!' it's great! (correct)

So this case was a bug in the old version, and the new behavior is correct. No breaking change for users.

Verification

  • pnpm run build passes
  • pnpm test: 29 files / 642 tests passed
  • Added a test in lib/command-parser/expand-arguments.spec.ts for an argument with both ' and !. It passes with 1.12.0 and fails with 1.9.0.
  • pnpm audit no longer reports shell-quote

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coveralls

coveralls commented Oct 7, 2026 •

Copy link
Copy Markdown

Coverage Status

coverage: 98.83%. remained the same — Mayvis:fix/bump-shell-quote into open-cli-tools:main

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Mayvis

Mayvis commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

I added a test (efe9536) in lib/command-parser/expand-arguments.spec.ts for a passthrough argument that contains both ' and ! (it's great!). This is the only quote() output that differs between 1.9.0 and 1.12.0.

  • With 1.12.0 the test passes: echo 'it'"'"'s great!'
  • With 1.9.0 it fails, because the old output "it's great\!" leaves a stray backslash in sh/bash.

Full suite: 29 files / 642 tests passed.

@omonk

omonk commented Oct 7, 2026

Copy link
Copy Markdown

Duplicate of #622

@Mayvis

Mayvis commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

You're right, thanks for pointing that out. #622 was opened first and fixes the same CVE. 1.12.0 doesn't add anything relevant over 1.11.0 for concurrently (the extra changes only affect object tokens, which concurrently never passes to quote()).

The one thing this PR adds is a regression test in lib/command-parser/expand-arguments.spec.ts for a passthrough argument containing both ' and !. The quote() output for that case changed in 1.11.0 (fixing a stray backslash), so the test applies to #622 as-is.

@Abicodexi, feel free to cherry-pick efe9536 into #622. I'll close this PR in favor of yours. I've also opened #626 to track the CVE; #622 could reference it with Closes #626.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade shell-quote to >=1.11.0 to fix CVE-2026-102422

3 participants