CVE-2026-9277
Red Hat shell-quote, Cryostat 4 on RHEL 9, Cluster Observability Operator 1.5.0 취약점
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2)...
- 대응 우선순위
- 점검
- CVSS
- 9.2
- EPSS
- 0.85% 백분위 53.9% · 2026.07.15 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.22