Back to Vulnerability Directory
HIGHFixed upstream
CVE-2024-27980
Node.js: command injection via child_process.spawn with batch files on Windows
Technology
Node.js
CVSS Score
8.1 / 10.0
Affected Versions
Node.js 18, 20 and 21 on Windows before the April 2024 releases
Upstream Fix
18.20.2; 20.12.2; 21.7.3
Published
January 9, 2025
OSSeva Coverage
Fixed upstream
Description
Improper handling of batch files in child_process.spawn and spawnSync on Windows let a malicious command line argument inject arbitrary commands and achieve code execution even when the shell option was not enabled. Rated High by Node.js. Fixed in 18.20.2, 20.12.2 and 21.7.3. The fix was bypassed by CVE-2024-36138.
Is your Node.js deployment affected?
If you're running Node.js 18, 20 and 21 on Windows before the April 2024 releases, you need this patch. Book a discovery call to get covered.