Affected package: notify-send (npm), 0.1.2 and all earlier versions.
Weakness: CWE-78: Improper Neutralization of Special Elements used in an OS Command.
Fixed version: none available. See Maintenance status below.
Usage at the time of reporting: around 1,500 downloads a week.
What the problem is
notify-send shows desktop notifications by running the
notify-send binary. Its notify() function
(lib/notify-send.js) builds a command string and runs it through a shell with
child_process.exec. The notification summary and body are passed through Node's
util.inspect first, which produces a JavaScript string literal rather than a
shell-safe one; where the text already contains a single quote, util.inspect
switches to double quotes, inside which shell substitution still takes effect. The
-u, -i, -c and -t option values are
concatenated with no quoting at all.
The underlying mistake is worth naming plainly: util.inspect is a debugging
formatter, not a shell escaper.
Impact
Notification text is frequently derived from content the operator does not control, such as alerts, chat messages or build output. A project that notifies using such text hands its author the ability to run commands as the account the Node process runs under.
How to fix it
Run the external binary without a shell and pass each value as its own argument, using
child_process.execFile or child_process.spawn with an argument array. Every value
is then treated as literal text rather than as part of a command line. Quoting the values inside the
command string is not a reliable substitute.
Until a fixed release exists, projects depending on this package should either apply the change in a fork or move to a maintained alternative that does not build shell command strings from caller-supplied values.
Maintenance status
The latest release, 0.1.2, was published in July 2011 and the repository has not been updated since. It carries no security policy and no private reporting channel, so the report was made to MITRE as CNA of last resort. No fixed version is available.
Timeline
- 10 September 2026: reported to MITRE as CNA of last resort, the affected project having no security policy and no private reporting channel.
- 29 September 2026: CVE ID assigned.
- 30 September 2026: this advisory published as the public reference for the CVE record.
Credit and method
Reported by Brian Willows, Graith Internet. The finding and its analysis were AI-assisted, using Claude, and every claim was verified locally against the published package before the report was filed. The verification detail is held privately and is available to a maintainer or to a CVE numbering authority on request.
References
This advisory is published so that the CVE record has a public reference. Corrections are welcome at security@graith.co.uk.
