CVE-2026-9277
Red Hat shell-quote, Cryostat 4 on RHEL 9, Cluster Observability Operator 1.5.0
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2)...
- CVSS
- 9.2
- EPSS
- 0.85% 53.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.22