HIGH7.5
GHSA-3xgq-45jj-v275
Regular Expression Denial of Service (ReDoS) in cross-spawn
Quick fix
GHSA-3xgq-45jj-v275 — cross-spawn: upgrade to the fixed version with the command below.
npm install cross-spawn@7.0.5Details
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538[ADVISORY]
- https://github.com/moxystudio/node-cross-spawn/issues/165[WEB]
- https://github.com/moxystudio/node-cross-spawn/pull/160[WEB]
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff[WEB]
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f[WEB]
- https://github.com/moxystudio/node-cross-spawn/commit/d35c865b877d2f9ded7c1ed87521c2fdb689c8dd[WEB]
- https://github.com/moxystudio/node-cross-spawn[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349[WEB]
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230[WEB]