Executive brief
cross-spawn is a popular Node.js library used to run system commands across different operating systems. A vulnerability in how it handles special characters can allow an attacker to crash an application or cause it to become unresponsive by providing a specifically crafted input string. This results in a denial of service, potentially impacting application availability and increasing server CPU usage.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in cross-spawn's 'escape' utility. The root cause is inefficient regular expression complexity (CWE-1333) in the logic used to escape command-line arguments, specifically when handling sequences of backslashes followed by double quotes or the end of a string. An attacker can trigger catastrophic backtracking by providing a very large, specially crafted string (e.g., a long sequence of backslashes), leading to excessive CPU consumption and process hangs. The issue is fixed in versions 6.0.6 and 7.0.5 by altering the regex to disable backtracking.
Affected products
- moxystudio cross-spawn < 6.0.6, >= 7.0.0 < 7.0.5
Timeline
- 2024-11-06: patched: Initial fix for backtracking merged into master branch.
- 2024-11-08: advisory: Vulnerability disclosed and CVE-2024-21538 assigned.
- 2024-11-18: patched: Version 6.0.6 released with backported fix.
References
- https://github.com/moxystudio/node-cross-spawn/issues/165
- https://github.com/moxystudio/node-cross-spawn/pull/160
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f
- https://github.com/moxystudio/node-cross-spawn/commit/d35c865b877d2f9ded7c1ed87521c2fdb689c8dd
- https://github.com/moxystudio/node-cross-spawn