Home / mailings [SECURITY] [DSA 6548-1] node-shell-quote security update
Posted on 06 October 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6548-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
October 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : node-shell-quote
CVE ID : CVE-2026-13311 CVE-2026-102422
Debian Bug : 1140921 1149713
Two vulnerabilities were discovered in node-shell-quote, a Node.js
module to quote and parse shell commands, which could result in denial
of service or shell command injection.
For the stable distribution (trixie), these problems have been fixed in
version 1.7.4+~1.7.1-1+deb13u2.
We recommend that you upgrade your node-shell-quote packages.
For the detailed security status of node-shell-quote please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/node-shell-quote
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
