CVE-2024-27980
NONE EPSS 68.8%
Published Jan 9, 20251y ago · Modified Jun 17, 20262w ago
Published Jan 9, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Threat Intelligence
EPSS Exploit Probability
68.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-77 Command Injection Injection
References 5
- openwall.com http://www.openwall.com/lists/oss-security/2024/04/10/15
- openwall.com http://www.openwall.com/lists/oss-security/2024/07/11/6
- openwall.com http://www.openwall.com/lists/oss-security/2024/07/19/3
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5MZN6PFXHTCCUENAKZXTGWPKUAHI6E2W/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JUWBYDVCUSCX7YWTBX75LADMCVYFBGKU/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.