NPM · JULY 2026 · EARLY WARNING

shell-quote npm Package Vulnerability: Quadratic-complexity Denial of Service

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-395F-4HP3-45GVSeverity: HIGH

The shell-quote npm package is reportedly affected by a quadratic-complexity denial of service vulnerability in its `parse()` function. This issue can be exploited by an unauthenticated attacker to block the Node.js event loop, potentially causing a denial of service.

What happened

An early warning has been issued regarding a vulnerability in the shell-quote npm package. The issue, tracked as GHSA-395F-4HP3-45GV, involves a quadratic-complexity denial of service in the `parse()` function. This vulnerability allows an unauthenticated attacker to block the Node.js event loop for tens of seconds with a small input, leading to a denial of service.

The affected versions of shell-quote include: from '0' to '1.9.0', from '1.6.3' to '1.7.3', from '0' to '1.6.1', and from '1.1.0' to '1.8.4'. The vulnerability has been addressed in versions '1.9.0', '1.7.3', '1.6.1', and '1.8.4' respectively.

Professional software engineers are advised to monitor for updates to the shell-quote package. If a suitable fix is not released promptly, consider using alternative packages to mitigate potential risks. For more detailed information, consult the primary source at https://github.com/ljharb/shell-quote/security/advisories/GHSA-395f-4hp3-45gv.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If shell-quote is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats