fix: disable regexp backtracking by satazor · Pull Request #160 · moxystudio/node-cross-spawn (original) (raw)

@satazor

satazor added a commit that referenced this pull request

Nov 7, 2024

@satazor

@satazor satazor deleted the bugfix/regexp-backtrack branch

November 7, 2024 13:04

satazor added a commit that referenced this pull request

Nov 18, 2024

@satazor

@Scc33 Scc33 mentioned this pull request

Nov 18, 2024

This was referenced

Nov 19, 2024

Thompson1985

This was referenced

Dec 9, 2024

This was referenced

Jan 7, 2025

This was referenced

Jan 17, 2025

This was referenced

Feb 10, 2025

gurus00 pushed a commit to gurus00/node-cross-spawn that referenced this pull request

Feb 11, 2025

@satazor

This was referenced

Apr 11, 2025

This was referenced

May 8, 2025

highorbit25 added a commit to highorbit25/concert-vuln-app that referenced this pull request

Feb 5, 2026

@highorbit25

Resolves: #28

Vulnerability Details:

Remediation: Added npm overrides to force cross-spawn to version 7.0.5, which contains the security fix for this HIGH severity ReDoS vulnerability. The cross-spawn package is a transitive dependency of Next.js and other build tools.

This fix prevents Regular Expression Denial of Service (ReDoS) attacks that could cause CPU exhaustion and application crashes through crafted input strings.

Automated fix generated by IBM Bob based on CVE research from:

This was referenced

Feb 5, 2026

This was referenced

Mar 5, 2026

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})