Junglewise Threat Intelligence

CVE-2024-21538: moxystudio cross-spawn ReDoS in argument escaping

CVE-2024-21538 · Severity: low · CVSS 3.1 · Published 2024-11-08

Executive brief

cross-spawn is a popular Node.js library used to run system commands across different operating systems. A vulnerability in how it handles special characters can allow an attacker to crash an application or cause it to become unresponsive by providing a specifically crafted input string. This results in a denial of service, potentially impacting application availability and increasing server CPU usage.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in cross-spawn's 'escape' utility. The root cause is inefficient regular expression complexity (CWE-1333) in the logic used to escape command-line arguments, specifically when handling sequences of backslashes followed by double quotes or the end of a string. An attacker can trigger catastrophic backtracking by providing a very large, specially crafted string (e.g., a long sequence of backslashes), leading to excessive CPU consumption and process hangs. The issue is fixed in versions 6.0.6 and 7.0.5 by altering the regex to disable backtracking.

Affected products

  • moxystudio cross-spawn < 6.0.6, >= 7.0.0 < 7.0.5

Timeline

  • 2024-11-06: patched: Initial fix for backtracking merged into master branch.
  • 2024-11-08: advisory: Vulnerability disclosed and CVE-2024-21538 assigned.
  • 2024-11-18: patched: Version 6.0.6 released with backported fix.

References