CVE-2024-36138: Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Overview
- Severity
- High (CVSS 8.1)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2024-Sep
- Released
- 2026-08-07
- Last Updated
- 2026-08-12
- EPSS Score
- 1.10% (percentile: 63.7%)
Affected Products (3)
Other
- 19873
- 19873-21692
- 19608-17084
Revision History
- 2026-08-07: Information published.
- 2026-08-12: Information published.