GHSA-3xgq-45jj-v275
GitHub Security Advisory
Regular Expression Denial of Service (ReDoS) in cross-spawn
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Affected Packages
npm
cross-spawn
Affected versions:
7.0.0
(fixed in 7.0.5)
npm
cross-spawn
Affected versions:
0
(fixed in 6.0.6)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.