Vulnerability Description
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shell-Quote Project | Shell-Quote | < 1.6.1 |
Related Weaknesses (CWE)
References
- https://github.com/advisories/GHSA-qg8p-v9q4-gh34ExploitThird Party Advisory
- https://nodesecurity.io/advisories/117Third Party Advisory
- https://github.com/advisories/GHSA-qg8p-v9q4-gh34ExploitThird Party Advisory
- https://nodesecurity.io/advisories/117Third Party Advisory
FAQ
What is CVE-2016-10541?
CVE-2016-10541 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious u...
How severe is CVE-2016-10541?
CVE-2016-10541 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-10541?
Check the references section above for vendor advisories and patch information. Affected products include: Shell-Quote Project Shell-Quote.