StackRadar

CVE-2026-102422

Critical

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 18,035 indexed, latest versions
Container images
22
deployed by those charts
Fix available
2 of 2
affected packages

shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token

Carried by container images the latest versions of 22 of 18,035 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
node-shell-quotedeb1.7.4+~1.7.1-1+deb13u11.7.4+~1.7.1-1+deb13u22
shell-quotenpm1.8.4, 1.9.0, 1.10.01.11.022
OSV records
DEBIAN-CVE-2026-102422GHSA-pqg4-j6r4-53mv

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.431 of 1See more

n8n community-charts 1.24.43

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.687e0bab2c931
shell-quote@1.9.0
1.11.0

Open the chart page →

1,436
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
shell-quote@1.9.0
1.11.0

Open the chart page →

2,298
n8nhelmforgeVerified publisher2.1.31 of 2See more

n8n helmforge 2.1.3

1 of the 2 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.3fdce8f852ac7
shell-quote@1.9.0
1.11.0

Open the chart page →

1,797
umamihelmforgeVerified publisher2.3.41 of 3See more

umami helmforge 2.3.4

1 of the 3 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.4.085909afc45bd
shell-quote@1.10.0
1.11.0

Open the chart page →

1,957
betterdb-monitorbetterdb-monitorOfficialVerified publisher0.49.01 of 1See more

betterdb-monitor betterdb-monitor 0.49.0

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
shell-quote@1.10.0
1.11.0

Open the chart page →

421
dawarichcogitriVerified publisher2.9.21 of 3See more

dawarich cogitri 2.9.2

1 of the 3 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
node-shell-quote@1.7.4+~1.7.1-1+deb13u1
shell-quote@1.9.0
1.7.4+~1.7.1-1+deb13u2
1.11.0

Open the chart page →

6,999
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/data-fair/portals:18b621866ceb2
shell-quote@1.10.0
1.11.0

Open the chart page →

42,628
jellystatdjjudas21Verified publisher1.0.11 of 1See more

jellystat djjudas21 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.12e61c759ec706
shell-quote@1.8.4
1.11.0

Open the chart page →

2,101
plane-enterprisemakeplaneOfficialVerified publisher3.10.33 of 13See more

plane-enterprise makeplane 3.10.3

3 of the 13 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
makeplane/live-commercial:v3.3.1d68fab8f6a3e
shell-quote@1.10.0
1.11.0
makeplane/silo-commercial:v3.3.1f0825c6b22d1
shell-quote@1.10.0
1.11.0
makeplane/space-commercial:v3.3.19360e65bf273
shell-quote@1.10.0
1.11.0

Open the chart page →

6,159
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
shell-quote@1.8.4
1.11.0

Open the chart page →

36,191
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
shell-quote@1.10.0
1.11.0

Open the chart page →

4,830
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest8aa1c158d885
shell-quote@1.9.0
1.11.0

Open the chart page →

862
dawarichhelmforgeVerified publisher1.0.31 of 4See more

dawarich helmforge 1.0.3

1 of the 4 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
node-shell-quote@1.7.4+~1.7.1-1+deb13u1
shell-quote@1.9.0
1.7.4+~1.7.1-1+deb13u2
1.11.0

Open the chart page →

12,007
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
shell-quote@1.10.0
1.11.0

Open the chart page →

6,907
strapihelmforgeVerified publisher2.3.151 of 3See more

strapi helmforge 2.3.15

1 of the 3 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
shell-quote@1.10.0
1.11.0

Open the chart page →

2,725
cdashkitwareVerified publisher0.20.01 of 3See more

cdash kitware 0.20.0

1 of the 3 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
kitware/cdash:v5.4.0da5abe941506
shell-quote@1.10.0
1.11.0

Open the chart page →

13,265
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
shell-quote@1.9.0
1.11.0

Open the chart page →

2,298
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
shell-quote@1.9.0
1.11.0

Open the chart page →

2,298
code-serverquench-code-serverVerified publisher0.0.171 of 1See more

code-server quench-code-server 0.0.17

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/code-serverdigest-pinned805f781460ae
shell-quote@1.9.0
1.11.0

Open the chart page →

44
dawarichschichtelVerified publisher0.3.51 of 1See more

dawarich schichtel 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
freikin/dawarich:1.14.511826c67e4b1
node-shell-quote@1.7.4+~1.7.1-1+deb13u1
shell-quote@1.9.0
1.7.4+~1.7.1-1+deb13u2
1.11.0

Open the chart page →

6,797
infisicalsinextraVerified publisher0.6.11 of 1See more

infisical sinextra 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.166b911e3938ac
shell-quote@1.10.0
1.11.0

Open the chart page →

3,374
strapistrapi-xmv0.1.21 of 1See more

strapi strapi-xmv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-102422.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
shell-quote@1.10.0
1.11.0

Open the chart page →

957

Container images carrying it

22 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
freikin/dawarich:1.15.2e58334ca5697
node-shell-quote@1.7.4+~1.7.1-1+deb13u1
shell-quote@1.9.0
1.7.4+~1.7.1-1+deb13u2
1.11.0
2
n8nio/n8n:2.36.714c4285bc303
shell-quote@1.9.0
1.11.0
2
betterdb/monitor:0.49.0-no-ai97dcd2d2192f
shell-quote@1.10.0
1.11.0
1
cyfershepard/jellystat:1.1.12e61c759ec706
shell-quote@1.8.4
1.11.0
1
ducktors/turborepo-remote-cache:latest8aa1c158d885
shell-quote@1.9.0
1.11.0
1
freikin/dawarich:1.14.511826c67e4b1
node-shell-quote@1.7.4+~1.7.1-1+deb13u1
shell-quote@1.9.0
1.7.4+~1.7.1-1+deb13u2
1.11.0
1
helmforge/strapi-base:5.52.270e9143d6d92
shell-quote@1.10.0
1.11.0
1
infisical/infisical:v0.165.166b911e3938ac
shell-quote@1.10.0
1.11.0
1
kitware/cdash:v5.4.0da5abe941506
shell-quote@1.10.0
1.11.0
1
makeplane/live-commercial:v3.3.1d68fab8f6a3e
shell-quote@1.10.0
1.11.0
1
makeplane/silo-commercial:v3.3.1f0825c6b22d1
shell-quote@1.10.0
1.11.0
1
makeplane/space-commercial:v3.3.19360e65bf273
shell-quote@1.10.0
1.11.0
1
n8nio/n8n:2.41.687e0bab2c931
shell-quote@1.9.0
1.11.0
1
n8nio/n8n:2.36.8cfe2704ff858
shell-quote@1.9.0
1.11.0
1
n8nio/n8n:2.41.3fdce8f852ac7
shell-quote@1.9.0
1.11.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
shell-quote@1.8.4
1.11.0
1
ghcr.io/data-fair/portals:18b621866ceb2
shell-quote@1.10.0
1.11.0
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
shell-quote@1.10.0
1.11.0
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
shell-quote@1.10.0
1.11.0
1
ghcr.io/quenchworks/images/code-server805f781460ae
shell-quote@1.9.0
1.11.0
1
ghcr.io/umami-software/umami:3.4.085909afc45bd
shell-quote@1.10.0
1.11.0
1
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
shell-quote@1.10.0
1.11.0
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.