Improper Control of Generation of Code ('Code Injection') Affecting nodejs/node package, versions [,18.20.4)[20.0.0,20.15.1)[22.0.0,22.4.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.1% (62nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NODEJSNODE-10669665
  • published9 Jul 2025
  • disclosed9 Jul 2024
  • creditTianst

Introduced: 9 Jul 2024

CVE-2024-36138  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade nodejs/node to version 18.20.4, 20.15.1, 22.4.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection'). This is due to a bypass of CVE-2024-27980.

A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Note: This vulnerability affects only users of child_process.spawn and child_process.spawnSync on Windows in all active release lines.

CVSS Base Scores

version 4.0
version 3.1