-
Notifications
You must be signed in to change notification settings - Fork 30.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Disallow args in child_process execFile/spawn when the shell option is true #57143
Labels
child_process
Issues and PRs related to the child_process subsystem.
Comments
What behavior do you think it should have? Should it throw an error when the second argument isn't empty? |
Since spawn/execFile already allow omitting |
What kind of error should it throw? |
DanielVenable
added a commit
to DanielVenable/node
that referenced
this issue
Feb 24, 2025
This will make it throw an error when args are passed to execFile or spawn when the shell option is true. The reason for this is that when it accepts args, it gives the false impression that the args are escaped while really they are just concatenated. This makes it easy to introduce bugs and security vulnerabilities. This will break any code that relies on passing args to execFile or spawn with `{ shell: true }`. Fixes: nodejs#57143
DanielVenable
added a commit
to DanielVenable/node
that referenced
this issue
Feb 24, 2025
This will make it throw an error when args are passed to execFile or spawn when the shell option is true. The reason for this is that when it accepts args, it gives the false impression that the args are escaped while really they are just concatenated. This makes it easy to introduce bugs and security vulnerabilities. This will break any code that relies on passing args to execFile or spawn with `{ shell: true }`. Fixes: nodejs#57143
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The
execFile
andspawn
functions allow passing the shell option to run a command using a shell. Despite the fact that setting this option to true means that arguments are no longer properly preserved, these functions continue to accept an array of arguments, giving the false impression that there is some isolation/escaping when behind the scenes the arguments are just concatenated. This can make it trivial to introduce bugs and security issues, and the behavior is also not aligned withexec
which only accepts a single command string that is passed to the shell. To make this point clearer, invocations like this are currently accepted, which shouldn't be the case:The text was updated successfully, but these errors were encountered: