CVE-2024-3566 | Node.js up to 18.20.1/20.12.1/21.7.2 on Windows CreateProcess os command injection (VU#123335)
A vulnerability classified as critical has been found in Node.js up to 18.20.1/20.12.1/21.7.2 on Windows. The affected element is the function CreateProcess. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-3566. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.