← Back to CVE List
CVE-2024-27980
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt