FlawAtlas
Search the atlas
CVE-2024-36138 Not scored

CVE-2024-36138

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

Exploit probability 1.1%
Published September 7, 2024
Required by Not available
Last source change June 24, 2026

03 / CONNECTIONS

Connected vulnerabilities

related CGA-9M92-4R7Q-86J5
related OPENSUSE-SU-2024:14435-1
related OPENSUSE-SU-2025:15802-1
related SUSE-SU-2024:2496-1
related SUSE-SU-2024:2542-1
related SUSE-SU-2024:2543-1
related SUSE-SU-2024:2574-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-36138

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

View original source

05 / REFERENCES

Further evidence