NA

CVE-2024-27980

Vulnerability Summary

Description<!---->A command injection flaw was found in Node.js exclusive to Windows environments. This flaw allows an malicious user to perform command injection via the args parameter of child_process.spawn without the shell option enabled on Windows. This behavior is caused by cmd.exe when executing batch files, which has complicated parsing rules for arguments that were not able to be safely escaped. It is possible to inject commands if an attacker can control part of the command arguments of the batch file.A command injection flaw was found in Node.js exclusive to Windows environments. This flaw allows an malicious user to perform command injection via the args parameter of child_process.spawn without the shell option enabled on Windows. This behavior is caused by cmd.exe when executing batch files, which has complicated parsing rules for arguments that were not able to be safely escaped. It is possible to inject commands if an attacker can control part of the command arguments of the batch file.

Vulnerability Trend

Vendor Advisories

Description<!---->A command injection flaw was found in Nodejs exclusive to Windows environments This flaw allows an attacker to perform command injection via the args parameter of child_processspawn without the shell option enabled on Windows This behavior is caused by cmdexe when executing batch files, which has complicated parsing rules for ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> NodeJS Command injection via args parameter of child_processspawn without shell option enabled on Windows (CVE-2024-27980) <! ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Fwd: Nodejs security update for all active relesae lines, April 9 2024 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...