Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade nodejs18Upgrade nodejs22-docsUpgrade corepack18Upgrade nodejs22Upgrade nodejs20-develUpgrade npm18Upgrade corepack20Upgrade npm20Upgrade nodejs20Upgrade nodejs18-docsUpgrade nodejs18-develUpgrade npm22Upgrade nodejs20-docsUpgrade corepack22Upgrade nodejs22-devel | Jul 17, 2024 | Jul 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub