Skip to content

chore(deps): bump cross-spawn to v7.0.5 [SECURITY]#454

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-cross-spawn-vulnerability
Open

chore(deps): bump cross-spawn to v7.0.5 [SECURITY]#454
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-cross-spawn-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Nov 19, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
cross-spawn 7.0.37.0.5 age adoption passing confidence

Regular Expression Denial of Service (ReDoS) in cross-spawn

CVE-2024-21538 / GHSA-3xgq-45jj-v275

More information

Details

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

Severity

  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

moxystudio/node-cross-spawn (cross-spawn)

v7.0.5

Compare Source

v7.0.4

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file deps-prod labels Nov 19, 2024
@renovate renovate Bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-cross-spawn-vulnerability branch March 27, 2026 00:49
@renovate renovate Bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed chore(deps): bump cross-spawn to v7.0.5 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-cross-spawn-vulnerability branch 2 times, most recently from 98099cd to 365ac4a Compare March 30, 2026 17:47
@renovate renovate Bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot changed the title chore(deps): bump cross-spawn to v7.0.5 [SECURITY] - autoclosed chore(deps): bump cross-spawn to v7.0.5 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-cross-spawn-vulnerability branch 2 times, most recently from 365ac4a to 9fd51e0 Compare April 27, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deps-prod

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants