CVE-2024-27980

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Jan 9, 2025
CWE ID 77

Summary

CVE-2024-27980 is a newly disclosed vulnerability affecting the way Node.js handles batch files in child_process.spawn and child_process.spawnSync. Malicious command line arguments can exploit this issue to inject arbitrary commands and execute code, bypassing the need for the shell option to be enabled. This vulnerability poses a significant risk to Node.js applications that use these functions to spawn processes. Attackers can potentially gain unauthorized access or modify data if they successfully exploit this vulnerability. Users are strongly encouraged to update their Node.js installations as soon as a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share