Skip to content

libnpmexec: escape executable name on Windows (cmd injection via npx) - #10095

Open
kalt2212 wants to merge 1 commit into
npm:latestfrom
kalt2212:fix-npx-windows-cmd-injection
Open

kalt2212 wants to merge 1 commit into
npm:latestfrom
kalt2212:fix-npx-windows-cmd-injection

Conversation

@kalt2212

@kalt2212 kalt2212 commented Oct 8, 2026

Copy link
Copy Markdown

Commit 6901bb1 escaped the executable name in libnpmexec run-script for non-Windows shells, but the Windows branch was left raw. A package with a malicious bin entry (e.g. "x&calc") reaches cmd.exe /d /s /c unescaped when the victim runs npx on Windows -- cmd.exe interprets &, |, <, > and %VAR%, giving arbitrary command execution as the user (CWE-78).

This mirrors the existing non-Windows escaping for the Windows branch: double-quote the name (so & | < > ^ are literal), double % (still expands inside quotes) and use "" for embedded quotes.

Static end-to-end trace verified; preflight clean (no existing issue/CVE for this pattern).

Commit 6901bb1 escaped the executable name for non-Windows shells but
left the Windows branch raw: a malicious bin entry (e.g. "x&calc")
reaches cmd.exe /d /s /c unescaped, allowing arbitrary command
execution as the user on npx.
@kalt2212
kalt2212 requested a review from a team as a code owner October 8, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant