zx is vulnerable to OS Command Injection
50
Medium Risk
Affected versions of this package are vulnerable to a command injection issue in the kill() function of the zx library on Windows, where the pid parameter is unsafely interpolated into a shell command via child_process.exec() without validation, allowing attackers controlling the input to execute arbitrary commands. An attacker can exploit this by injecting shell metacharacters into the pid argument, as demonstrated in the PoC where supplying '1234 & calc.exe' launches the calculator, proving remote code execution that could lead to full system compromise.
You are affected if you are using a version that falls within the vulnerable range, and if you are running the package on a Windows environment.
zx is vulnerable to OS Command Injection in versions 8.5.0 - 8.8.1.
Upgrade the zx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant