node is vulnerable to Command injection
80
High Risk
Due to improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution, even if the shell option is not enabled.
This vulnerability affects all users in active release lines: 18.x, 20.x, 21.x but it is only exploitable on Windows.
node is vulnerable to Command injection in versions 21.0.0 - 21.7.2, 20.0.0 - 20.12.1 and 18.0.0 - 18.20.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant