Intel

AIKIDO-2025-10898

batch-cluster is vulnerable to Improper Cleanup on Thrown Exception

Improper Cleanup on Thrown Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 9, 2025

20

Low Risk

This Affects:

JSbatch-cluster
7.0.0 - 15.0.1
Fixed in 16.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Improper Process Termination on stdin.write() Errors, where errors during stdin.write() operations fail to properly terminate the process, leaving a broken process in the pool. An attacker could exploit this by repeatedly triggering stdin.write() errors to exhaust process pool resources, causing denial of service.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

batch-cluster is vulnerable to Improper Cleanup on Thrown Exception in versions 7.0.0 - 15.0.1.

How to fix this

Upgrade the batch-cluster library to the patch version.