Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-27980

Node.js: command injection via child_process.spawn with batch files on Windows

Technology

Node.js

CVSS Score

8.1 / 10.0

Affected Versions

Node.js 18, 20 and 21 on Windows before the April 2024 releases

Upstream Fix

18.20.2; 20.12.2; 21.7.3

Published

January 9, 2025

OSSeva Coverage

Fixed upstream

Description

Improper handling of batch files in child_process.spawn and spawnSync on Windows let a malicious command line argument inject arbitrary commands and achieve code execution even when the shell option was not enabled. Rated High by Node.js. Fixed in 18.20.2, 20.12.2 and 21.7.3. The fix was bypassed by CVE-2024-36138.

Upstream record: NVD · CVE.org

Is your Node.js deployment affected?

If you're running Node.js 18, 20 and 21 on Windows before the April 2024 releases, you need this patch. Book a discovery call to get covered.