Repository navigation
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
I added a test (efe9536) in
Full suite: 29 files / 642 tests passed. |
|
Duplicate of #622 |
|
You're right, thanks for pointing that out. #622 was opened first and fixes the same CVE. 1.12.0 doesn't add anything relevant over 1.11.0 for concurrently (the extra changes only affect object tokens, which concurrently never passes to The one thing this PR adds is a regression test in @Abicodexi, feel free to cherry-pick efe9536 into #622. I'll close this PR in favor of yours. I've also opened #626 to track the CVE; #622 could reference it with |
Closes #626
Summary
Bumps
shell-quotefrom1.9.0to1.12.0to address CVE-2026-102422 / GHSA-pqg4-j6r4-53mv (critical):quote()command injection via a line terminator in a token after a{ comment }token.>=1.8.4 <1.11.01.11.0concurrently uses
quote()fromshell-quoteinlib/command-parser/expand-arguments.ts.Compatibility
concurrently only calls
quote()inlib/command-parser/expand-arguments.ts, to escape passthrough arguments substituted into the{1},{@}and{*}placeholders, and it always passes an array of strings.Changes in
quote.jsbetween1.9.0and1.12.0:{ comment }), new operators and glob handling only apply to object tokens, so they never apply to concurrently.",$, backticks,~, backslashes, newlines, empty string, etc.) and they are identical.'and!, e.g.it's great!:quote()outputsh/bash"it's great\!"it's great\!(stray backslash, wrong)'it'"'"'s great!'it's great!(correct)So this case was a bug in the old version, and the new behavior is correct. No breaking change for users.
Verification
pnpm run buildpassespnpm test: 29 files / 642 tests passedlib/command-parser/expand-arguments.spec.tsfor an argument with both'and!. It passes with1.12.0and fails with1.9.0.pnpm auditno longer reportsshell-quote🤖 Generated with Claude Code