StackRadar

CVE-2021-42740

Critical

Advisory

Published 24 May 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.042
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Improper Neutralization of Special Elements used in a Command in Shell-quote

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
shell-quotenpm1.7.21.7.315
OSV records
GHSA-g4rg-993r-mgx7

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
shell-quote@1.7.2
1.7.3

Open the chart page →

5,251
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
shell-quote@1.7.2
1.7.3

Open the chart page →

3,476
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
shell-quote@1.7.2
1.7.3

Open the chart page →

3,444
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
shell-quote@1.7.2
1.7.3

Open the chart page →

7,517
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
shell-quote@1.7.2
1.7.3

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
shell-quote@1.7.2
1.7.3

Open the chart page →

12,907
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
shell-quote@1.7.2
1.7.3

Open the chart page →

3,744
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
shell-quote@1.7.2
1.7.3

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
shell-quote@1.7.2
1.7.3

Open the chart page →

3,651
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.7.3

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.7.3

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.7.3

Open the chart page →

12,108
mojaloopmojaloop14.0.02 of 6See more

mojaloop mojaloop 14.0.0

2 of the 6 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.7.3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.7.3

Open the chart page →

19,226
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
shell-quote@1.7.2
1.7.3

Open the chart page →

6,438
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
shell-quote@1.7.2
1.7.3

Open the chart page →

5,215
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
shell-quote@1.7.2
1.7.3

Open the chart page →

3,696
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-42740.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
shell-quote@1.7.2
1.7.3

Open the chart page →

20,270

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.7.3
3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.7.3
2
arfath29/3-tier-app-frontend:latest384b3e377f47
shell-quote@1.7.2
1.7.3
1
conduction/conduction-ui-app:devd591f5e6f2a9
shell-quote@1.7.2
1.7.3
1
gristlabs/grist:0.7.96e71b1914a7e
shell-quote@1.7.2
1.7.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
shell-quote@1.7.2
1.7.3
1
lsstsqre/squareone:0.4.09ded78e7fe03
shell-quote@1.7.2
1.7.3
1
misskey/misskey:12.110.1e08b7c478093
shell-quote@1.7.2
1.7.3
1
ondrejsika/parking:latestb1fd497416c8
shell-quote@1.7.2
1.7.3
1
samajh/alprfrontend:latest05ef4fddbb75
shell-quote@1.7.2
1.7.3
1
testhubio/testhub-frontend:on-preme86c2db53be8
shell-quote@1.7.2
1.7.3
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
shell-quote@1.7.2
1.7.3
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
shell-quote@1.7.2
1.7.3
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
shell-quote@1.7.2
1.7.3
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
shell-quote@1.7.2
1.7.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.