Security vulnerabilities and automated fixes for react devtools issues
1 post found
A critical command injection vulnerability (CVE-2026-9277) was discovered in shell-quote 1.8.3, where unescaped line terminators could allow arbitrary code execution. The vulnerability was fixed by upgrading to shell-quote 1.9.0, which properly escapes line terminators in the react-devtools-core dependency chain, preventing attackers from breaking out of quoted strings to inject malicious commands.