Skip to content

Conversation

@gardera-security
Copy link

Update cross-spawn to 7.0.5, 6.0.6

Merge this pull request to resolve a vulnerability in cross-spawn.

high - CVE-2024-21538: cross-spawn: regular expression denial of service

Description

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

References

Publish date

2024-11-08 05:15:06.453000+00:00

@gardera-security gardera-security bot added the dependencies Pull requests that update a dependency file label May 12, 2025
Copy link
Author

@gardera-security gardera-security bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gardera Security Scan Results


🛡️ Scan Summary

No security issues were identified in this scan.

@patriknordlen patriknordlen deleted the gardera/npm/cross-spawn-7.0.3 branch June 24, 2025 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants