StackRadar

CVE-2026-13311

High

Advisory

Published 20 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
83
deployed by those charts
Fix available
1 of 1
affected package

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 83 images.

Affected packageAffected versionsFixed inImages
shell-quotenpm1.4.3, 1.6.1, 1.7.2, 1.7.3+6 more1.9.083
OSV records
GHSA-395f-4hp3-45gv

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
shell-quote@1.8.3
1.9.0

Open the chart page →

3,555
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
shell-quote@1.7.2
1.9.0

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
shell-quote@1.7.2
1.9.0

Open the chart page →

3,651
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.9.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.9.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.9.0

Open the chart page →

12,108
mojaloopmojaloop14.0.02 of 6See more

mojaloop mojaloop 14.0.0

2 of the 6 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.9.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.9.0

Open the chart page →

19,226
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
shell-quote@1.7.2
1.9.0

Open the chart page →

6,438
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
shell-quote@1.8.1
1.9.0

Open the chart page →

4,560
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
shell-quote@1.8.3
1.9.0

Open the chart page →

4,016
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
shell-quote@1.8.1
1.9.0

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
shell-quote@1.8.1
1.9.0

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
shell-quote@1.8.1
1.9.0

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
shell-quote@1.8.1
1.9.0

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
shell-quote@1.8.0
1.9.0

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
shell-quote@1.7.3
1.9.0

Open the chart page →

3,269
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
shell-quote@1.8.3
1.9.0

Open the chart page →

3,798
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
shell-quote@1.8.1
1.9.0

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
shell-quote@1.8.1
1.9.0

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
shell-quote@1.8.0
1.9.0

Open the chart page →

15,187
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
shell-quote@1.7.3
1.9.0

Open the chart page →

838
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
shell-quote@1.8.1
1.9.0

Open the chart page →

2,969
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
shell-quote@1.4.3
1.9.0

Open the chart page →

5,215
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
shell-quote@1.8.3
1.9.0

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
shell-quote@1.7.3
1.9.0

Open the chart page →

7,413
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
shell-quote@1.7.4
1.9.0

Open the chart page →

1,796
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
shell-quote@1.8.1
1.9.0

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
shell-quote@1.7.3
1.9.0

Open the chart page →

3,143
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
shell-quote@1.7.2
1.9.0

Open the chart page →

3,696
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
shell-quote@1.8.1
1.9.0

Open the chart page →

7,574
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
shell-quote@1.6.1
1.9.0

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
shell-quote@1.6.1
1.9.0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
shell-quote@1.6.1
1.9.0

Open the chart page →

12,460
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
shell-quote@1.7.2
1.9.0

Open the chart page →

20,270
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
shell-quote@1.8.2
1.9.0

Open the chart page →

5,228
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-13311.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
shell-quote@1.7.4
1.9.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
shell-quote@1.7.4
1.9.0

Open the chart page →

16,083

Container images carrying it

83 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
shell-quote@1.7.2
1.9.0
3
pantsel/konga:latestc8172b75607d
shell-quote@1.6.1
1.9.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
shell-quote@1.8.1
1.9.0
3
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
shell-quote@1.6.1
1.9.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
shell-quote@1.7.2
1.9.0
2
rajnandan1/kener:3.2.1930407afca731
shell-quote@1.8.2
1.9.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
shell-quote@1.7.3
1.9.0
2
0hlov3/semaphore:v1.0.050f874ec096b
shell-quote@1.7.4
1.9.0
1
apimap/developer:v1.3.1406d3858e20c
shell-quote@1.7.3
1.9.0
1
apimap/portal:v2.4.0041a4790c65c
shell-quote@1.7.3
1.9.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
shell-quote@1.7.2
1.9.0
1
assistiot/open_api_frontend:1.0.1f11d82defc70
shell-quote@1.8.0
1.9.0
1
baserow/baserow:1.30.1df0c42eb67e8
shell-quote@1.8.1
1.9.0
1
ccjacobs14/amazon:59a9b14a6f09e
shell-quote@1.8.1
1.9.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
shell-quote@1.7.4
1.9.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
shell-quote@1.7.2
1.9.0
1
cspconsole/report-processor:1.0.279a2d8840bfdf
shell-quote@1.8.1
1.9.0
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
shell-quote@1.8.4
1.9.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
shell-quote@1.8.1
1.9.0
1
fallenbagel/jellyseerr:latest4538137bc5af
shell-quote@1.8.3
1.9.0
1
gristlabs/grist:0.7.96e71b1914a7e
shell-quote@1.4.3
1.9.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
shell-quote@1.8.0
1.9.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
shell-quote@1.8.1
1.9.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
shell-quote@1.7.3
1.9.0
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
shell-quote@1.6.1
1.9.0
1
joplin/server:3.0-beta52af57880c0e
shell-quote@1.7.3
1.9.0
1
joplin/server:2.14.2-betab87564ef34e9
shell-quote@1.7.4
1.9.0
1
konradkleine/docker-registry-frontend:v2181aad54ee64
shell-quote@1.4.3
1.9.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
shell-quote@1.8.1
1.9.0
1
kyso/kyso-front:lateste52595c5c16f
shell-quote@1.8.1
1.9.0
1
lavandadelpatio/frontend:latest501c3f31e0bc
shell-quote@1.7.2
1.9.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
shell-quote@1.8.1
1.9.0
1
lissy93/dashy:2.0.51991f7be5ed0
shell-quote@1.7.3
1.9.0
1
lsstsqre/squareone:0.4.09ded78e7fe03
shell-quote@1.7.2
1.9.0
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
shell-quote@1.6.1
1.9.0
1
misskey/misskey:12.110.1e08b7c478093
shell-quote@1.7.2
1.9.0
1
mitchxxx/amazon:214e72480ec63a
shell-quote@1.8.1
1.9.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
shell-quote@1.8.1
1.9.0
1
n8nio/n8n:2.25.7761374d4eb84
shell-quote@1.8.3
1.9.0
1
nocodb/nocodb:0.301.5d9516f0bf546
shell-quote@1.8.3
1.9.0
1
ondrejsika/parking:latestb1fd497416c8
shell-quote@1.7.2
1.9.0
1
ooghenekaro/amazon:latest03394ba1d6d8
shell-quote@1.8.1
1.9.0
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
shell-quote@1.7.3
1.9.0
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
shell-quote@1.8.1
1.9.0
1
outlinewiki/outline:0.82.0494dfb9249a6
shell-quote@1.8.1
1.9.0
1
samajh/alprfrontend:latest05ef4fddbb75
shell-quote@1.7.2
1.9.0
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
shell-quote@1.6.1
1.9.0
1
soulteary/cronicle:0.9.80ac2512fa6e39
shell-quote@1.7.3
1.9.0
1
testhubio/testhub-frontend:on-preme86c2db53be8
shell-quote@1.7.2
1.9.0
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
shell-quote@1.7.4
1.9.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.