CVE-2024-36138
EUVD-2024-3589507.09.2024, 16:15
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nodejs | nodejs | 18.0 ≤ 𝑥 < 18.20.4 | ADP |
| nodejs | nodejs | 20.0 ≤ 𝑥 < 20.15.1 | ADP |
| nodejs | nodejs | 22.0 ≤ 𝑥 < 22.4.1 | ADP |
Debian Releases
Ubuntu Releases