VDB
Sign up
HIGH7.5

GHSA-3xgq-45jj-v275

Regular Expression Denial of Service (ReDoS) in cross-spawn

Quick fix

GHSA-3xgq-45jj-v275 — cross-spawn: upgrade to the fixed version with the command below.

npm install cross-spawn@7.0.5

Details

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/cross-spawn
Introduced in: 7.0.0Fixed in: 7.0.5
Fixnpm install cross-spawn@7.0.5
npm/cross-spawn
Introduced in: 0Fixed in: 6.0.6
Fixnpm install cross-spawn@6.0.6

References